osvcheck
Lightweight vulnerability scanner for Python dependencies using the OSV database.
osvcheck scans your Python project's dependencies for known security vulnerabilities by querying the OSV (Open Source Vulnerabilities) database. It's designed for source-level checking during development and CI/CD pipelines.
Key features:
- Zero runtime dependencies (stdlib only)
- Auto-detects package manager (uv.lock, uv, or pip)
- Smart caching (12-48 hour TTL) minimizes API calls
- Distinguishes direct vs indirect vulnerabilities
- Optional rich integration for enhanced output (auto-detected if installed)
Installation
Install via pip or uv, or add to your project's dev dependencies.
Usage
# Scan current project
osvcheck
# Logging options
osvcheck -v # Verbose (debug) output
osvcheck -q # Quiet (warnings/errors only)
osvcheck --log-json # JSON format logs
osvcheck --log-file FILE # Write logs to file
# Color control
osvcheck --color # Force color output
osvcheck --no-color # Disable color output
Exit codes:
0- No vulnerabilities found1- Indirect dependency vulnerabilities only2- Direct dependency vulnerabilities found
As a Pre-commit hook:
Add to .pre-commit-config.yaml:
- repo: https://github.com/deeprave/osvcheck
rev: v1.0.1
hooks:
- id: osvcheck
CI/CD integration:
# Fail only on direct vulnerabilities
osvcheck || [ $? -eq 1 ]
# Fail on any vulnerabilities
osvcheck
Features
- Scans Python dependencies for known security vulnerabilities
- Uses the OSV (Open Source Vulnerabilities) database
- Multi-environment support with auto-detection:
- Uses
uv.lockif present and up-to-date (fastest) - Falls back to
uv pip listif uv is available - Falls back to
pip listif pip is available
- Uses
- Smart caching with 12-48 hour randomized TTL
- Distinguishes between direct and indirect dependency vulnerabilities
- Zero runtime dependencies (Python stdlib only)
- Optional rich integration for enhanced output (auto-detected if already installed)
License
MIT License - See LICENSE file for details.
Metadata
Release files for osvcheck 1.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| osvcheck-1.4.0.tar.gz | 10.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| osvcheck-1.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.4 kB
Release files / osvcheck-1.4.0.tar.gz
| Download URL | osvcheck-1.4.0.tar.gz |
|---|---|
| Size | 10.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0c73f2af5328d8e1b286057ecea3ee48a119a8bd4256f87d326f38fefca3daa0
|
|
BLAKE2b-256 checksum How to use checksums |
0281ffbf850020a52acdaec355a04e1440f4c178396194b6a139389acd406457
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 9, 2026.
Transparency logRelease files / osvcheck-1.4.0-py3-none-any.whl
| Download URL | osvcheck-1.4.0-py3-none-any.whl |
|---|---|
| Size | 14.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8deebb2124d6f020cc9b89d6d3e50860278a157db89cff42cf7b26f1d9482a98
|
|
BLAKE2b-256 checksum How to use checksums |
6fde8261ea856da221e99f0d82328f450ae3847cf8298bd7a397a724ab107307
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 9, 2026.
Transparency log