Skip to content
#

osv-scanner

Here are 24 public repositories matching this topic...

Deterministic code quality gate for AI coding agents (Claude Code, Codex, pi): git hooks that block test tampering, hold the CRAP bar on changed functions, check diff coverage, secrets and dependencies. 12 languages, one config file. Optional Jev classifier for test hunks.

  • Updated Sep 28, 2026
  • TypeScript
osv-scanner

Fork of Google's OSV-Scanner with my fix for a stack-overflow DoS in the SPDX license parser (issue #2993, PR #3032): unbounded recursion on untrusted license expressions, now bounded with a depth limit.

  • Updated Sep 6, 2026
  • Go

A 5-second morning supply-chain safety check for npm/PyPI/Docker/Go/Rust: known-malicious packages, CVEs, zero-hour deps, release-cooldown & digest pinning, plus build-manifest and AI-agent-config auto-exec checks (Shai-Hulud/Miasma). Zero-dependency CLI + Claude Code plugin.

  • Updated Aug 4, 2026
  • JavaScript

Open-source CVE vulnerability management platform for SOC teams. Centralize scanner results, enrich vulnerabilities with threat intelligence (KEV, EPSS, NVD), track remediation and automate response workflows.

  • Updated Jul 7, 2026
  • Python

Deterministic broker that drives Claude Code and Grok through a detect, analyze, fix, verify loop against a target repo. Detectors find the bugs, the agents reason and patch, and no fix counts until the broker re-runs the repro itself.

  • Updated Sep 29, 2026
  • TypeScript
vulnfy

Vulnfy is a lightweight, cross-platform dependency and container vulnerability scanner written in Python. It automatically detects project configuration/lock files across multiple languages and ecosystems, queries the OSV API, and generates a structured JSON vulnerability report.

  • Updated Sep 21, 2026
  • Python

Add this topic to your repo

To associate your repository with the osv-scanner topic, visit your repo's landing page and select "manage topics."

Learn more