tldr/pages/common/osv-scanner.md
Fernando Fontana cbac3166ae
osv-scanner: add page (#9831)
* osv-scanner: add page

The Open Source Vulnerability (OSV) Database is a distributed vulnerability database for open source ecosystems.

* Apply suggestions from code review

Co-authored-by: Jack Lin <blueskyson1401@gmail.com>

* osv-scanner: fix syntax

---------

Co-authored-by: Jack Lin <blueskyson1401@gmail.com>
2023-02-07 11:00:18 +08:00

590 B

osv-scanner

Scan various mediums for dependencies and matches them against the OSV database. More information: https://osv.dev/about.

  • Scan a docker image:

osv-scanner -D {{docker_image_name}}

  • Scan a package lockfile:

osv-scanner -L {{path/to/lockfile}}

  • Scan an SBOM file:

osv-scanner -S {{path/to/sbom_file}}

  • Scan multiple directories recursively:

osv-scanner -r {{directory1 directory2 ...}}

  • Skip scanning git repositories:

osv-scanner --skip-git {{-r|-D}} {{target}}

  • Output result in JSON format:

osv-scanner --json {{-D|-L|-S|-r}} {{target}}