Skip to content
application-security

OSV

Open Source Vulnerability Database

Definition

OSV is a distributed vulnerability database for open-source software, initiated by Google, that aggregates vulnerability data from ecosystem-specific sources like GitHub Advisory Database, PyPI Advisory Database, and RustSec. It uses a machine-readable JSON schema that links vulnerabilities to precise affected version ranges for packages across multiple ecosystems.

The OSV.dev API enables tools to query vulnerability status for any open-source dependency.


Ship secure code faster

Crash Override integrates security into the developer workflow. No context switching, no waiting on reviews.