googleSecurity & privacy

osv.dev

Open source vulnerability database and triage service providing a unified query API and web interface

  • Backend
  • DevOps
  • Security
  • Productivity
  • Web
  • API/SDK
  • Library/framework
  • Linux
  • macOS
  • Windows
  • Browser
  • Self-hostable
  • Runs locally
  • Docker supported
osv.dev screenshot
Popularity
2.9k Stars
GitHub stars
Recent activity
8/20/2026
Updated in the last 30 days
License
APACHE-2.0
Permissive

Why it matters

We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.

Last 90 days

Problem

Open source projects face known dependency vulnerabilities, requiring data aggregation and triage across multiple sources.

Practical value

Provides a centralized vulnerability database, Web UI, API, data dumps, and scanning support for lockfiles, containers, SBOMs, and Git repositories.

Innovation / differentiation

Integrates multi-ecosystem versioning helpers, vulnerability conversion feeds, and an indexing and worker architecture running on GCP.

Leverage potential

Integrates with third-party tools and ecosystems such as Cortex XSOAR, Dependency-Track, Trivy, Renovate, and pip-audit.

Why now

Continues to advance multi-source vulnerability aggregation and distribution services as software supply chain security gains attention.

Community activity

In the last 90 days there were 53 new issues and 386 pull requests; the bounded issue/PR samples include 33 issue authors and 13 PR contributors, with 0 releases.

Maintainer responsiveness

The 53-issue window sample had a 53% close rate, and the 100-pull-request sample had a 97% merge rate. Maintainer-response observations covered 62% of that issue sample, with a 9% response rate and median first response of 0.3 hours.

13 contributors in PR sample0 releasesIssue response rate 9% · sample 33 (62% coverage)Median first response 0.3hPR merge rate 97% · 100 sampled in window

Key highlights

  • Provides a unified open source vulnerability database and query API
  • Supports accessing full vulnerability data dumps via GCS
  • Includes tools for ecosystem package versioning and feed conversion

Quick start

How it is installed, how hard it is, and where to start.

Where it runs

Self-hosted (your own server)

Difficulty

Medium — some setup needed

Docker supportedSelf-hostableRuns locally
  1. 01Clone the repository and initialize submodules
  2. 02Update submodules using git: git submodule update --init --recursive

Best for

  • Teams that want data on their own servers
  • Developers who want to try it on their machine
  • People who prefer Docker deploys

More about it

OSV.dev is an open source vulnerability database and triage service designed to aggregate and distribute security vulnerability data across open source ecosystems. It hosts the complete codebase required to run the osv.dev web service, including Python backend workers and ecosystem versioning logic.

Users can query known vulnerabilities via the web UI, REST API, or data dumps. The project integrates with the companion osv-scanner tool to check dependencies across lockfiles, Debian containers, SBOMs, and Git repositories.

Sources

Each field shows its status and source — expand to review.

15 · Expand
  • capability tags

    Verified

    security, productivity

    Source: admin_cms · cms editor · 8/21/2026

  • editor note

    Verified

    {"en":"This project maintains the core code for the Google OSV service, supporting vulnerability queries via API and dependency scanning through the companion osv-scanner tool.","zh":"该项目维护 Google OSV 服务的核心代码,支持通过 API 查询或配合独立的 osv-scanner 工具扫描依赖锁文件和容器。"}

    Source: admin_cms · cms editor · 8/21/2026

  • how to use

    Verified

    {"steps":[{"en":"Clone the repository and initialize submodules","zh":"克隆项目代码库并初始化子模块"},{"en":"Update submodules using git: git submodule update --init --recursive","zh":"使用 Git 命令更新子模块:git submodule update --init --recursive"}],"installAt":"self_host","difficulty":"medium"}

    Source: admin_cms · cms editor · 8/21/2026

  • intro

    Verified

    {"en":"OSV.dev is an open source vulnerability database and triage service designed to aggregate and distribute security vulnerability data across open source ecosystems. It hosts the complete codebase required to run the osv.dev web service, including Python backend workers and ecosystem versioning logic.\n\nUsers can query known vulnerabilities via the web UI, REST API, or data dumps. The project integrates with the companion osv-scanner tool to check dependencies across lockfiles, Debian containers, SBOMs, and Git repositories.","zh":"OSV.dev 是一个开源漏洞数据库与分诊服务,聚合和分发开源生态系统中的安全漏洞信息。该项目托管了运行 osv.dev 网站所需的全部代码、Python 后端工作进程以及生态系统版本处理逻辑。\n\n用户可以通过官方 Web 界面、REST API 或数据导出功能查询已知漏洞。项目同时支持配合独立的 osv-scanner 客户端工具,对项目锁文件、Debian 容器、SBOM 及 Git 仓库进行依赖项漏洞检查。"}

    Source: admin_cms · cms editor · 8/21/2026

  • Latest release

    Verified

    v0.1.3

    Source: GitHub API · latest_release=v0.1.3 · 8/20/2026

  • License

    Verified

    Apache-2.0

    Source: GitHub API · license.spdx_id=Apache-2.0 · 8/20/2026

  • needs api key

    Verified

    No

    Source: admin_cms · cms editor · 8/21/2026

  • One-liner

    Verified

    {"en":"Open source vulnerability database and triage service providing a unified query API and web interface","zh":"开源漏洞数据库与分类服务,提供统一的漏洞查询 API 和 Web 界面"}

    Source: admin_cms · cms editor · 8/21/2026

  • Platforms

    Verified

    linux, macos, windows, browser

    Source: admin_cms · cms editor · 8/21/2026

  • Category hint

    Inferred from materials

    security

    Source: Project README · hint=security · 8/20/2026

  • product forms

    Verified

    web, api_sdk, library_framework

    Source: admin_cms · cms editor · 8/21/2026

  • role tags

    Verified

    backend, devops, security

    Source: admin_cms · cms editor · 8/21/2026

  • supports docker

    Verified

    Yes

    Source: admin_cms · cms editor · 8/21/2026

  • supports local

    Verified

    Yes

    Source: admin_cms · cms editor · 8/21/2026

  • supports self host

    Verified

    Yes

    Source: admin_cms · cms editor · 8/21/2026

Other verified projects matched by category, capabilities, and intended roles.