OSV Scanner is a tool by Google that finds vulnerabilities in projects. It can scan documentation files, project lock files, or SBOM files. You can install it as a command-line binary or as a Docker container.
Chapters
0:00 Intro
0:31 Example Setup
1:02 SBOM Scanning
1:19 Vulnerability OSV Page
1:31 NPM Lock File Scanning
1:53 Vulnerability OSV Page Again
1:56 Directory Scanning
3:03 Installation
3:37 Conclusion
3:58 What Could be Better
4:20 Thanks For Watching!
Resources
🎯 GitHub: https://github.com/google/osv-scanner
🎯 Learn More About SPDX: https://spdx.dev/
🎯 Learn More About CycloneDX: https://cyclonedx.org/
More Great SBOM Resources!
🌐 https://learnsbom.com
Contact Us!
📨 [email protected]
#sbom