googleSecurity & privacy
osv.dev
Open source vulnerability database and triage service providing a unified query API and web interface
- Backend
- DevOps
- Security
- Productivity
- Web
- API/SDK
- Library/framework
- Linux
- macOS
- Windows
- Browser
- Self-hostable
- Runs locally
- Docker supported

- Popularity
- 2.9k Stars
- GitHub stars
- Recent activity
- 8/20/2026
- Updated in the last 30 days
- License
- APACHE-2.0
- Permissive
Why it matters
We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.
Problem
Open source projects face known dependency vulnerabilities, requiring data aggregation and triage across multiple sources.
Practical value
Provides a centralized vulnerability database, Web UI, API, data dumps, and scanning support for lockfiles, containers, SBOMs, and Git repositories.
Innovation / differentiation
Integrates multi-ecosystem versioning helpers, vulnerability conversion feeds, and an indexing and worker architecture running on GCP.
Leverage potential
Integrates with third-party tools and ecosystems such as Cortex XSOAR, Dependency-Track, Trivy, Renovate, and pip-audit.
Why now
Continues to advance multi-source vulnerability aggregation and distribution services as software supply chain security gains attention.
Community activity
In the last 90 days there were 53 new issues and 386 pull requests; the bounded issue/PR samples include 33 issue authors and 13 PR contributors, with 0 releases.
Maintainer responsiveness
The 53-issue window sample had a 53% close rate, and the 100-pull-request sample had a 97% merge rate. Maintainer-response observations covered 62% of that issue sample, with a 9% response rate and median first response of 0.3 hours.
Key highlights
- Provides a unified open source vulnerability database and query API
- Supports accessing full vulnerability data dumps via GCS
- Includes tools for ecosystem package versioning and feed conversion
Quick start
How it is installed, how hard it is, and where to start.
Where it runs
Self-hosted (your own server)
Difficulty
Medium — some setup needed
- 01Clone the repository and initialize submodules
- 02Update submodules using git: git submodule update --init --recursive
Best for
- Teams that want data on their own servers
- Developers who want to try it on their machine
- People who prefer Docker deploys
More about it
OSV.dev is an open source vulnerability database and triage service designed to aggregate and distribute security vulnerability data across open source ecosystems. It hosts the complete codebase required to run the osv.dev web service, including Python backend workers and ecosystem versioning logic.
Users can query known vulnerabilities via the web UI, REST API, or data dumps. The project integrates with the companion osv-scanner tool to check dependencies across lockfiles, Debian containers, SBOMs, and Git repositories.
Sources
Each field shows its status and source — expand to review.
15 · Expand
Sources
Each field shows its status and source — expand to review.
capability tags
Verifiedsecurity, productivity
Source: admin_cms · cms editor · 8/21/2026
editor note
Verified{"en":"This project maintains the core code for the Google OSV service, supporting vulnerability queries via API and dependency scanning through the companion osv-scanner tool.","zh":"该项目维护 Google OSV 服务的核心代码,支持通过 API 查询或配合独立的 osv-scanner 工具扫描依赖锁文件和容器。"}
Source: admin_cms · cms editor · 8/21/2026
how to use
Verified{"steps":[{"en":"Clone the repository and initialize submodules","zh":"克隆项目代码库并初始化子模块"},{"en":"Update submodules using git: git submodule update --init --recursive","zh":"使用 Git 命令更新子模块:git submodule update --init --recursive"}],"installAt":"self_host","difficulty":"medium"}
Source: admin_cms · cms editor · 8/21/2026
intro
Verified{"en":"OSV.dev is an open source vulnerability database and triage service designed to aggregate and distribute security vulnerability data across open source ecosystems. It hosts the complete codebase required to run the osv.dev web service, including Python backend workers and ecosystem versioning logic.\n\nUsers can query known vulnerabilities via the web UI, REST API, or data dumps. The project integrates with the companion osv-scanner tool to check dependencies across lockfiles, Debian containers, SBOMs, and Git repositories.","zh":"OSV.dev 是一个开源漏洞数据库与分诊服务,聚合和分发开源生态系统中的安全漏洞信息。该项目托管了运行 osv.dev 网站所需的全部代码、Python 后端工作进程以及生态系统版本处理逻辑。\n\n用户可以通过官方 Web 界面、REST API 或数据导出功能查询已知漏洞。项目同时支持配合独立的 osv-scanner 客户端工具,对项目锁文件、Debian 容器、SBOM 及 Git 仓库进行依赖项漏洞检查。"}
Source: admin_cms · cms editor · 8/21/2026
Latest release
Verifiedv0.1.3
Source: GitHub API · latest_release=v0.1.3 · 8/20/2026
License
VerifiedApache-2.0
Source: GitHub API · license.spdx_id=Apache-2.0 · 8/20/2026
needs api key
VerifiedNo
Source: admin_cms · cms editor · 8/21/2026
One-liner
Verified{"en":"Open source vulnerability database and triage service providing a unified query API and web interface","zh":"开源漏洞数据库与分类服务,提供统一的漏洞查询 API 和 Web 界面"}
Source: admin_cms · cms editor · 8/21/2026
Platforms
Verifiedlinux, macos, windows, browser
Source: admin_cms · cms editor · 8/21/2026
Category hint
Inferred from materialssecurity
Source: Project README · hint=security · 8/20/2026
product forms
Verifiedweb, api_sdk, library_framework
Source: admin_cms · cms editor · 8/21/2026
role tags
Verifiedbackend, devops, security
Source: admin_cms · cms editor · 8/21/2026
supports docker
VerifiedYes
Source: admin_cms · cms editor · 8/21/2026
supports local
VerifiedYes
Source: admin_cms · cms editor · 8/21/2026
supports self host
VerifiedYes
Source: admin_cms · cms editor · 8/21/2026
Related projects
Other verified projects matched by category, capabilities, and intended roles.
openbao
An open-source secrets management system for storing, distributing, rotating, and controlling access to secrets, certificates, and keys.
agent-governance-toolkit
A governance toolkit for AI agents that adds policy checks, identity, audit trails, sandboxing, and SRE controls across multiple agent frameworks.
CVE Lite CLI
A local-first JavaScript/TypeScript lockfile vulnerability scanner focused on actionable remediation, with CI, SARIF, HTML reports, and offline advisory data.
prismor
A self-hosted runtime security control plane for AI coding agents, providing real-time monitoring, blocking, and human-in-the-loop approval for tool calls.
fleet
A device-management platform for IT and security teams covering MDM, software deployment, patching, inventory queries, and compliance across desktop and mobile operating systems.
VirusDetector
A Manifest V3 Chrome/Edge extension that detects Silver Fox Trojan phishing and spoofed websites using multi-rule scoring and download blocking.
