bomber

OSV is the default provider for bomber. It is an open, precise, and distributed approach to producing and consuming vulnerability information for open source.

You don’t need to register for any service, get a password, or a token. Just use bomber without a provider flag and away you go like this:

bomber scan test.cyclonedx.json

Supported ecosystems

At this time, the OSV supports the following ecosystems:

OSV Notes

Additionally, there are cases where OSV does not return a Severity, or a CVE/CWE. In these rare cases, bomber will output “UNSPECIFIED”, and “UNDEFINED” respectively.