{"id":2667,"date":"2025-03-18T10:05:12","date_gmt":"2025-03-18T10:05:12","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/18\/google-released-open-source-version-of-osv-scanner-tool-for-vulnerability-scanning\/"},"modified":"2025-03-18T10:05:12","modified_gmt":"2025-03-18T10:05:12","slug":"google-released-open-source-version-of-osv-scanner-tool-for-vulnerability-scanning","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/18\/google-released-open-source-version-of-osv-scanner-tool-for-vulnerability-scanning\/","title":{"rendered":"Google Released Open Source Version of OSV-Scanner Tool for Vulnerability Scanning"},"content":{"rendered":"<p>    Google Released Open Source Version of OSV-Scanner Tool for Vulnerability Scanning<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has officially launched OSV-Scanner V2.0.0, a major upgrade to its open-source vulnerability scanning tool.\u00a0<\/p>\n<p>Released on March 17, 2025, this new version represents a significant evolution in helping developers identify and fix security vulnerabilities in their software dependencies.<\/p>\n<p>The V2 <a href=\"https:\/\/security.googleblog.com\/2025\/03\/announcing-osv-scanner-v2-vulnerability.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">release<\/a> builds upon the foundation laid with OSV-SCALIBR and introduces substantial new features that transform OSV-Scanner into a comprehensive vulnerability detection and remediation platform.\u00a0<\/p>\n<p>Originally launched in December 2022, OSV-Scanner has become an essential tool for open-source security, providing developers with easy access to vulnerability information relevant to their projects.<\/p>\n<p>\u201cThis V2 release builds upon the foundation we laid with OSV-SCALIBR and adds significant new capabilities to OSV-Scanner, making it a comprehensive vulnerability scanner and remediation tool with broad support for formats and ecosystems,\u201d notes the Google Open Source Security Team<\/p>\n<h2 class=\"wp-block-heading\"><strong>Key Innovations in V2<\/strong><\/h2>\n<p>The most notable advancements in OSV-Scanner V2 include:<\/p>\n<h4 class=\"wp-block-heading\"><strong>Enhanced Dependency Extraction with OSV-SCALIBR: <\/strong><\/h4>\n<p>The release represents the first major integration of OSV-SCALIBR features into OSV-Scanner, significantly expanding support for various dependencies.<\/p>\n<p>New supported formats include:<\/p>\n<ul class=\"wp-block-list\">\n<li>.NET: deps.json<\/li>\n<li>Python: uv.lock<\/li>\n<li>JavaScript: bun.lock<\/li>\n<li>Haskell: cabal.project.freeze, stack.yaml.lock<\/li>\n<li>Multiple artifacts including Node modules, Python wheels, Java uber jars, and Go binaries<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\"><strong>Layer-Aware Container Scanning <\/strong><\/h4>\n<p>OSV-Scanner V2 introduces comprehensive scanning for Debian, <a href=\"https:\/\/cybersecuritynews.com\/ubuntu-printing-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ubuntu<\/a>, and Alpine container images, providing:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdOjp2ANrC3m-DkUTe27uB8DXdw0h0-gyr7sjwHpVdo0hALOO1JUamuvmZCH35P86FfCqrfBE2X0hvWJ41ypXv4jPYdUZuSRjuvcNyrpHfFvW1upJPQnrm0cEyy8yOGaRN3jZbA?key=bJ-senDW3TWmLfd1CSYmD9xA\" alt=\"\"><\/figure>\n<\/div>\n<p>This feature offers layer analysis showing where packages were introduced, layer history, base image identification, and vulnerability filtering specific to container environments.<\/p>\n<h4 class=\"wp-block-heading\"><strong>Interactive HTML Output<\/strong><\/h4>\n<p>The new HTML report format provides enhanced visualization capabilities, including severity breakdown, filtering options, and detailed vulnerability information.\u00a0<\/p>\n<p>For container images, it adds layer filtering and base image identification features, available through the command:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXd7hg-dzxTCP-oggiAac566iJ_Sba7KVDO-De8E6O06HAqSTUxUGtaW5TlUeu691BnhgWphu1490u3x3BPXMOU-35jKZ-DGo799r0xD4xoq7a7-7AgRsaNJY2MIbbLKziKtNhJsFQ?key=bJ-senDW3TWmLfd1CSYmD9xA\" alt=\"\"><\/figure>\n<\/div>\n<p>This makes vulnerability information more accessible and actionable.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcn5nP83ewkN-RjTm0OuX08Rsd1dYKLmmlXR1bTTgI0emaMf0SSCDomsh3CdzTcCPprnecKpWzQtF2dCOxZcqfkOVlMPeyE0lTxQABRAD3mgz4ugn3qKi5ROjLMe65yY-iys_93BA?key=bJ-senDW3TWmLfd1CSYmD9xA\" alt=\"\"><figcaption class=\"wp-element-caption\">HTML output for container image scanning<\/figcaption><\/figure>\n<\/div>\n<p>Guided Remediation for Maven: Building on the guided remediation feature for <a href=\"https:\/\/cybersecuritynews.com\/lazarus-hackers-weaponized-6-npm-packages\/\" target=\"_blank\" rel=\"noreferrer noopener\">npm packages<\/a>, V2 now extends this capability to Java through Maven pom.xml support:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdrsPXSFGgSPq-vit3LSI9L6L6aCdn5T3l7aA9x2mmNT4JkP0vlaJQ5GKcafM-FSmMsYYg1Y-GM6qSu0Y74BJwY7gaHVrDFIt0b0rO1bqmyVGKc5wbIfDBA-km0rpENJtXK-h7BlQ?key=bJ-senDW3TWmLfd1CSYmD9xA\" alt=\"\"><\/figure>\n<\/div>\n<p>This allows developers to remediate direct and transitive dependency vulnerabilities through direct version updates or dependency management overrides.<\/p>\n<p>While incorporating numerous improvements, OSV-Scanner V2 includes breaking changes aimed at future-proofing the tool.\u00a0The release includes a comprehensive migration guide to ensure a smooth upgrade process for existing users.\u00a0<\/p>\n<p>Some notable changes include guided remediation defaulting to non-interactive mode, experimental flags being removed, and merged license flags.<\/p>\n<p>The OSV-Scanner tool provides significant benefits compared to closed-source alternatives.\u00a0<\/p>\n<p>As an open-source, distributed vulnerability database, OSV offers high-quality advisories that can be improved by community contributions, resulting in precise, machine-readable vulnerability information that maps accurately to package dependencies.<\/p>\n<p>Developers across various programming languages can now utilize OSV-Scanner V2 to enhance their security posture and efficiently manage vulnerability remediation in their open-source dependencies. <\/p>\n<p>OSV-Scanner is available for immediate download from the official <a href=\"https:\/\/github.com\/google\/osv-scanner?tab=readme-ov-file\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitHub repository<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong><strong><code><strong>Are you from SOC\/DFIR Teams? \u2013 Analyse Malware Incidents &amp; get live Access with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=ti_feeds&amp;utm_content=demo&amp;utm_term=110325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/google-released-open-source-version-of-osv-scanner-tool\/\">Google Released Open Source Version of OSV-Scanner Tool for Vulnerability Scanning<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/google-released-open-source-version-of-osv-scanner-tool\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Released Open Source Version of OSV-Scanner Tool for Vulnerability Scanning Google has officially launched OSV-Scanner V2.0.0, a major upgrade to its open-source vulnerability scanning tool.\u00a0 Released on March 17, 2025, this new version represents a significant evolution in helping developers identify and fix security vulnerabilities in their software dependencies. The V2 release builds upon [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-2667","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2667"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2667"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2667\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}