Technical and passive OSINT · Open-source components
OSV-Scanner
Licence or access: Apache-2.0
- license status
- Apache-2.0
- purpose and i o
- authorized manifests/lockfiles/SBOMs/images → package advisory matches
- integration fit
- CLI/Go, offline DB, JSON/SARIF/SBOM
- passive profile and limitations
- public artifact must be confidently attributed; package match does not prove deployed/reachable code
- official source
- Repository
Official sources
- Repository https://github.com/google/osv-scanner
Catalogued at the 2026-09-01 research baseline. Verify the licence, free-tier limits, API schema and source terms again before deployment, and record a version-pinned registry entry for whatever you select.
Source: file 05 · 2-deployable-open-source-components · line 18