NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #311 by repository stars
Last release 2 years ago
no release in 18 months
Ships on a steady schedule
a new release about every 2 weeks
Most releases are documented
notes for 30 of 37 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
209 releases · first in 2022
One column per quarter.
Bug #574 Support versions with build metadata in yarn.lock files
Nothing published for this version
Nothing published for this version
Feature #534 New SARIF format that separates out individual vulnerabilities, see https://github.com/google/osv-scanner/issues/216
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #452 Add (experimental) rust call analysis, detect whether vulnerable functions are actually called in your Rust project! See our documentatio…
go version and checks for vulnerabilities in the standard library.osv-scanner.json for osv-scanner to scan. See our documentation for instructions.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #439 Create models.PURLToPackage(), and deprecate osvscanner.PURLToPackage().
models.PURLToPackage(), and deprecate osvscanner.PURLToPackage().PURLToPackage not returning the full namespace of packages in ecosystems
that use them (e.g. golang).Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #409 Adds an additional column to the table output which shows the severity if available.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #390 Add an user agent to OSV API requests.
Bug #237 Clarify when no vulnerabilities are found.
--hash.pkg/osv to allow overriding the http client / transportNothing published for this version
Nothing published for this version
Nothing published for this version
Bug #341 Make the reporter public to allow calling DoScan with non nil reporters.
--sbom.Nothing published for this version
Nothing published for this version
Nothing published for this version
Bug #319 Fix segmentation fault when parsing CycloneDX without dependencies.
Feature #304 OSV-Scanner now runs faster when there's multiple vulnerabilities.
--experimental-call-analysis flag.-r
flag in requirements.txt files.IgnoredVulns also ignore aliases.file: dependencies in pnpm lockfiles.Pipenv.lock files.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature #220 Vulnerability output is ordered deterministically.
/var/lib/dpkg/status. Thanks @cmaritan--lockfile.--format flag..gitignore files by default when scanning.conan.lock lockfiles and ecosystem Thanks @SSE4Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This update adds support for NuGet ecosystem and various bug fixes by the community.
This update adds support for NuGet ecosystem and various bug fixes by the community.
Nothing published for this version
Nothing published for this version
This is a minor patch release to mitigate human readable output issues on narrow terminals (#85).
This is a minor patch release to mitigate human readable output issues on narrow terminals (#85).
Nothing published for this version
Bug #52: Fixes 0 exit code being wrongly emitted when vulnerabilities are present.
Various bug fixes and improvements. Many thanks to the amazing contributions and suggestions from the community!
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →