-
Notifications
You must be signed in to change notification settings - Fork 540
Pull requests: google/osv-scanner
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
datasource: reject non-HTTPS Maven registry URLs to prevent credential exfiltration via pom.xml
#2671
opened Mar 22, 2026 by
djvirus9
Loading…
output: sanitize \r in gh-annotations to prevent GitHub Actions workflow command injection
#2669
opened Mar 22, 2026 by
djvirus9
Loading…
fix: prevent path traversal in ParentPOMPath via relativePath validation
#2668
opened Mar 21, 2026 by
johanr-8
Loading…
fix: add a newline to separate "no issues found" from logs
#2665
opened Mar 19, 2026 by
G-Rath
Loading…
fix(output): remove second newline at end of vertical output
#2664
opened Mar 19, 2026 by
G-Rath
Loading…
feat: support regex matching for package name overrides
#2658
opened Mar 19, 2026 by
majiayu000
Loading…
fix: correctly output packages from osv-scanner.json source in spdx format
#2641
opened Mar 12, 2026 by
Mananshah237
Loading…
feat: Add configuration option to disable scanning Go version from go.mod
#2637
opened Mar 11, 2026 by
another-rex
Loading…
feat: Move away from github-pages gem and add ruby 4 support for docs
#2588
opened Mar 4, 2026 by
hopkincame
Loading…
feat: add experimental support for updating config files
#2534
opened Feb 19, 2026 by
G-Rath
Loading…
feat: Scan Homebrew inventory using git repository metadata
#2510
opened Feb 11, 2026 by
Avgor46
Loading…
feat: migrate guided remediation to osv-scalibr implementation
#2413
opened Dec 12, 2025 by
michaelkedar
Loading…
ProTip!
Find all pull requests that aren't related to any open issues with -linked:issue.