osv.dev (Open Source Vulnerabilities) is Google’s open source platform and API for aggregating, managing, and analyzing vulnerability data across multiple ecosystems. It powers the osv.dev
website, providing a unified, queryable database of vulnerabilities that map directly to open source packages and versions. The system hosts vulnerability data for ecosystems such as PyPI, npm, Go, Maven, and Debian, among others. The platform includes a web UI, API, and a Go-based dependency scanner that checks software dependencies, container images, SBOMs (SPDX, CycloneDX), and Git repositories for known vulnerabilities. This repository contains the full infrastructure code for deploying osv.dev on Google Cloud Platform, including Terraform configurations, APIs, data pipelines, indexers, and background workers for vulnerability ingestion and impact analysis. It also integrates with automated feeds from sources like NVD and OSS-Fuzz, enabling continuous updates and high data accuracy.

Features

  • Unified vulnerability database with structured, machine-readable data
  • Public REST API for querying vulnerabilities by package and version
  • Go-based scanner for analyzing dependencies, SBOMs, and containers
  • Automated ingestion from NVD, OSS-Fuzz, and other vulnerability feeds
  • GCP-based infrastructure with indexers, workers, and cloud functions
  • Data dumps and public instance available

Project Samples

Project Activity

See All Activity >

Categories

Database

License

Apache License V2.0

Follow OSV.dev

OSV.dev Web Site

Other Useful Business Software
AI-generated apps that pass security review Icon
AI-generated apps that pass security review

Stop waiting on engineering. Build production-ready internal tools with AI—on your company data, in your cloud.

Retool lets you generate dashboards, admin panels, and workflows directly on your data. Type something like “Build me a revenue dashboard on my Stripe data” and get a working app with security, permissions, and compliance built in from day one. Whether on our cloud or self-hosted, create the internal software your team needs without compromising enterprise standards or control.
Try Retool free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of OSV.dev!

Additional Project Details

Operating Systems

Linux, Mac, Windows

Programming Language

Go, Python, Unix Shell

Related Categories

Unix Shell Database Software, Python Database Software, Go Database Software

Registered

2025-10-10