Loading...
Loading...
Run Google's OSV-Scanner for Software Composition Analysis. Scans lockfiles and SBOMs across all major ecosystems (npm, PyPI, Maven, Go, Cargo, NuGet, RubyGems) for known vulnerabilities.
npx skill4agent add vchirrav/product-security-ai-skills sca-osv-scannergo install github.com/google/osv-scanner/cmd/osv-scanner@latestosv-scanner --versionosv-scanner -r --json <target-directory> > osv-results.jsonosv-scanner --lockfile=package-lock.json --jsonosv-scanner --sbom=sbom.json --jsonosv-scanner -r --skip-git --json <directory>| # | OSV ID | Severity | Package | Installed Version | Fixed Version | Summary | Ecosystem |
|---|--------|----------|---------|-------------------|---------------|---------|-----------|| Ecosystem | Lockfile |
|---|---|
| npm | |
| Python | |
| Go | |
| Rust | |
| Java | |
| .NET | |
| Ruby | |
| PHP | |