Check open-source packages for known vulnerabilities using the Google OSV database. Search by single package or paste your lock file for bulk scanning. Supports npm, PyPI, Go, Maven, and more.
Related free tools
Look up any CVE by ID or keyword and filter by CVSS severity.
Generate Subresource Integrity hashes so a tampered CDN script cannot load.
See exactly which versions your lockfile ranges resolve to.
Read next
Why a lockfile lookup misses transitive, vendored and reachability context — and what full SCA adds.
AquilaX SCA resolves the full transitive tree across npm, pip, Maven, Go, Cargo and more, flags licence conflicts, and opens upgrade PRs for vulnerable packages — with Securitron AI suppressing the unreachable ones.
Free plan is permanent · unlimited scans · GitHub, GitLab, Bitbucket & Azure DevOps