
OSV is the default provider for bomber. It is an open, precise, and distributed approach to producing and consuming vulnerability information for open source.
You don’t need to register for any service, get a password, or a token. Just use bomber without a provider flag and away you go like this:
bomber scan test.cyclonedx.json
At this time, the OSV supports the following ecosystems:
Additionally, there are cases where OSV does not return a Severity, or a CVE/CWE. In these rare cases, bomber will output “UNSPECIFIED”, and “UNDEFINED” respectively.