OSV
Find out whether the software you depend on has known security vulnerabilities, using OSV, the open vulnerability database run by Google's Open Source Security Team. One query reaches every source at once: GitHub advisories, the CVE catalogue, PyPI, Go, Rust and npm's own feeds, and the security trackers of Debian, Ubuntu, Alpine, Red Hat, SUSE, Android and the Linux kernel.
Check a single package, a Package URL from a bill of materials, a source repository at a tag, or a Git commit for code with no release at all; audit a whole lockfile or SBOM in one step; and read any advisory in full by its CVE or GHSA number. Setup is a single click: the API is keyless, so there is no account, no API key and no rate limit to manage.
Every answer says how bad the worst finding is and which release fixes it, in plain CRITICAL/HIGH/MEDIUM/LOW terms with a CVSS score beside it, so a scheduled workflow can raise a ticket or post to a channel the day something lands. Every vulnerability carries a link straight to its page on osv.dev.
Actions
Steps your workflow can run in OSV.
Connect in a few clicks
Authenticate once and every action and trigger for the app is ready to drop into a workflow. No glue code, no maintenance.
Automate across your stack
Chain apps together with triggers, actions, and logic that move data between your tools automatically, so work happens without you.
Secure by default
Credentials are encrypted and scoped per workspace. Connect the tools your team already trusts with confidence.
Automate OSV with Lodol.
Connect OSV and build your first workflow in minutes. No credit card required.
Free plan available · No credit card required
