Google Online Security Blog
Follow
Announcing OSV-Scanner V2: Vulnerability scanner and remediation tool for open source
The Google Open Source Security Team has released OSV-Scanner V2.0.0, a comprehensive vulnerability scanner and remediation tool with broad support for formats and ecosystems. This release builds upon the foundation laid by OSV-SCALIBR and adds significant new capabilities to OSV-Scanner. The integration of OSV-SCALIBR features into OSV-Scanner enables enhanced dependency extraction from projects and containers. OSV-Scanner V2 adds support for comprehensive, layer-aware scanning for Debian, Ubuntu, and Alpine container images. The tool can analyze container images to provide layer history, base images, and OS/distro information. A new interactive local HTML output format provides more interactivity and information compared to terminal-only outputs. Guided remediation for Maven pom.xml has been added, allowing for streamlined vulnerability management. The team plans to continue converging OSV-Scanner and OSV-SCALIBR, expand ecosystem support, and add features such as full filesystem accountability for containers and reachability analysis. Users can try OSV-Scanner V2 and contribute to its ongoing development by checking out the OSV-Scanner or OSV-SCALIBR repository. The team welcomes feedback and contributions to improve the platform and make vulnerability management easier for everyone.