NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #316 by repository stars
Last release 2 years ago
no release in 18 months
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 30 of 37 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
209 releases · first in 2022
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Bug #968 Hide unimportant Debian vulnerabilities to reduce noise.
Nothing published for this version
Nothing published for this version
Feature #934 add support for PNPM v9 lockfiles.
Nothing published for this version
Bug #899 Guided Remediation: Parse paths in npmrc auth fields correctly.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
(There is no Github release for this version)
(There is no Github release for this version)
MakeVersionRequestsWithContext()Nothing published for this version
Feature #352 Guided Remediation Introducing our new experimental guided remediation feature on osv-scanner fix subcommand. See our docs for detailed u
Feature #352 Guided Remediation
Introducing our new experimental guided remediation feature on osv-scanner fix subcommand.
See our docs for detailed usage instructions.
Feature #805 Include CVSS MaxSeverity in JSON output.
Bug #818 Align GoVulncheck Go version with go.mod.
Bug #797 Don't traverse gitignored dirs for gitignore files.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #754 Add dependency groups to flattened vulnerabilities output.
Feature #694
Add subcommands! OSV-Scanner now has subcommands! The base command has been moved to scan (currently the only commands is scan).
By default if you do not pass in a command, scan will be used, so CLI remains backwards compatible.
This is a building block to adding the guided remediation feature. See issue #352 for more details!
Feature #776 Add pdm lockfile support.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #655 Scan and report dependency groups (e.g. "dev dependencies") for vulnerabilities.
Feature #694 Add support for NuGet lock files version 2.
Feature #655 Scan and report dependency groups (e.g. "dev dependencies") for vulnerabilities.
Feature #702 Created an option to skip/disable upload to code scanning.
Feature #732 Add option to not fail on vulnerability being found for GitHub Actions.
Feature #729 Verify the spdx licenses passed in to the license allowlist.
Bug #736 Show ecosystem and version even if git is shown if the info exists.
Bug #703 Return an error if both license scanning and local/offline scanning is enabled simultaneously.
Bug #718 Fixed parsing of SBOMs generated by the latest CycloneDX.
Bug #704 Get go stdlib version from go.mod.
Reporter methods to add verbosity levels and to deprecate functions.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Return 1 if there are any findings (license violations or vulnerabilities).
renv files for the R language ecosystem.--experimental-call-analysis flag has now been updated to:--call-analysis=<language/all>
--no-call-analysis=<language/all>
with call analysis for Go enabled by default. See https://google.github.io/osv-scanner/usage/#scanning-with-call-analysis for the documentation!Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #621 Add support for scanning vendored C/C++ files.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →