Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Texas bill gives university boards power to reshape curriculum

June 2, 2025

One Tech Tip: How to use your smartphone to photograph the Northern Lights

June 2, 2025

Impressive Peony Garden in Michigan draws visitors from all over

June 2, 2025
Facebook X (Twitter) Instagram
Trending
  • Texas bill gives university boards power to reshape curriculum
  • One Tech Tip: How to use your smartphone to photograph the Northern Lights
  • Impressive Peony Garden in Michigan draws visitors from all over
  • Inside Washington Spirit Owner Michele Kang’s Plan To Revolutionize Women’s Soccer
  • Inside Panera And Cava Billionaire Ron Shaich’s Search For The Next Big Restaurant Chain
  • At-home health tests are here. But they aren’t always the best option
  • This steak salad is a trattoria staple and the perfect summer lunch
  • China blasts US for its computer chip moves and for threatening student visas
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Tuesday, June 3
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Google Releases Major Update for Open Source Vulnerability Scanner
Cybersecurity

Google Releases Major Update for Open Source Vulnerability Scanner

adminBy adminMarch 18, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 42


Google on Tuesday announced the release of an updated iteration of OSV-Scanner, its free vulnerability scanner for open source developers.

OSV-Scanner was introduced in 2022 as a front-end for the open source vulnerability database launched in 2021, to help developers receive detailed bug reports and improve the security of the open source ecosystem.

The new iteration of the scanner builds on the capabilities introduced earlier this year with the release of OSV-SCALIBR (Software Composition Analysis LIBRary), an extensible file system scanner that extracts information on software inventory.

OSV-Scanner V2.0.0 integrates OSV-SCALIBR features and becomes the official command-line code and container scanning tool for the open source library.

“This V2 release builds upon the foundation we laid with OSV-SCALIBR and adds significant new capabilities to OSV-Scanner, making it a comprehensive vulnerability scanner and remediation tool with broad support for formats and ecosystems,” Google says.

Courtesy of this integration, the scanner can now extract from projects source manifest and lockfiles (including .NET: deps.json, Python: uv.lock, JavaScript: bun.lock, and Haskell: cabal.project.freeze and stack.yaml.lock), and artifacts (such as Node modules, Python wheels, Java uber jars, and Go binaries).

It also includes layer-aware scanning for Alpine, Debian, and Ubuntu container images, providing details such as layer history and commands, layers where a package was introduced, the base image, the OS and distribution the container is running, and vulnerabilities unlikely to affect the container image.

OSV-Scanner V2.0.0 comes with a new interactive local HTML output format to deliver scan information such as flaw advisories, a breakdown on severity, and filtering of packages, IDs, and vulnerability importance.

Advertisement. Scroll to continue reading.

The scanner now includes guided remediation support for Maven to help address security defects in both direct and transitive dependencies, and provides support for reading and writing pom.xml files, for specifying a private registry to fetch metadata, and for updating dependencies in pom.xml to the latest version.

“We also introduced machine readable output for guided remediation that makes it easier to integrate guided remediation into your workflow,” Google notes.

The internet giant will continue to integrate OSV-SCALIBR functionality into OSV-Scanner’s CLI interface, expand support for additional ecosystems, add support for accounting for every file in a container image, integrate reachability analysis, and add support for Vulnerability Exchange (VEX).

OSV-Scanner V2.0.0 is available on GitHub, the same as OSV-SCALIBR, and Google welcomes feedback and contributions to both.

Related: UK Government Report Calls for Stronger Open Source Supply Chain Security Practices

Related: OpenSSF Releases Security Baseline for Open Source Projects

Related: Cyber Insights 2025: Open Source and Software Supply Chain Security

Related: Google Open Sources Security Patch Validation Tool for Android



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Inside Washington Spirit Owner Michele Kang’s Plan To Revolutionize Women’s Soccer

June 2, 2025

After selling her health care company, the billionaire is out to prove her three teams…

Inside Panera And Cava Billionaire Ron Shaich’s Search For The Next Big Restaurant Chain

June 2, 2025

J.K. Rowling Is A Billionaire—Again

May 30, 2025

Here Are 26 Others Who Made A Fortune In Beauty

May 30, 2025
Our Picks

Texas bill gives university boards power to reshape curriculum

June 2, 2025

One Tech Tip: How to use your smartphone to photograph the Northern Lights

June 2, 2025

Impressive Peony Garden in Michigan draws visitors from all over

June 2, 2025

Inside Washington Spirit Owner Michele Kang’s Plan To Revolutionize Women’s Soccer

June 2, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.