All 98 Dependencies

Every package OSV.dev depends on, ranked by repo health score.

OSV.dev is an open-source vulnerability database and triage platform built by Google that provides precise, version-aware vulnerability data for open source packages. Unlike generic CVE databases that describe vulnerabilities in prose, OSV maps each advisory directly to the affected package versions or commit hashes using a standardized machine-readable schema — enabling automated tools to determine exactly whether a specific installed version is vulnerable.

The platform aggregates advisories from GitHub Security Advisories, the Python Packaging Authority, RustSec, NVD, Alpine, Debian, Ubuntu, and more than 50 other ecosystems. All data is published under the open OSV schema adopted by OpenSSF and is freely accessible via a REST/gRPC API, bulk GCS data dumps at gs://osv-vulnerabilities, and a web UI at osv.dev.

Behind the scenes, OSV runs on Google Cloud Platform using a polyglot architecture: Python services handle the API layer, import pipeline, and core vulnerability processing, while Go powers the binary analysis indexer, NVD CVE converters, and API bindings. Workers deployed on GKE perform bisection analysis on git repositories to pinpoint when a vulnerability was introduced and fixed — producing version ranges that are more accurate than what upstream advisories report.

OSV.dev is also the data backbone for first-party tools like osv-scanner and is consumed by Trivy, Dependency-Track, pip-audit, Renovate, and the OSS Review Toolkit, making it a foundational piece of the open source supply chain security ecosystem.

20 packaging-legacy >=23.0.post0 31 jaraco.classes ==3.4.0 \ 36 Crashtest ==0.4.1 \ 36 findpython ==0.7.1 \ 39 h11 ==0.16.0 \ 39 packageurl-python ==0.17.6 40 distlib ==0.4.0 \ 41 jaraco.functools ==4.4.0 \ 41 requests-toolbelt ==1.0.0 \ 42 Shellingham ==1.5.4 \ 42 sjson v1.2.5 44 cvss ==3.6 45 markupsafe ==3.0.3 48 go-cmp v0.7.0 48 go-retryablehttp v0.7.8 48 gojsonschema v1.2.0 49 SecretStorage ==3.5.0 \ 53 Cleo ==2.1.0 \ 53 Jinja ==3.1.6 53 PyYAML ==6.0.3 53 httpcore ==1.0.9 \ 55 go-yaml v1.19.2 55 pbs-installer ==2025.12.17 \ 56 HTTPX ==0.28.1 \ 59 go-retry v0.3.0 outdated 59 whitenoise ==6.12.0 60 style-loader ^4.0.0 61 gjson v1.19.0 63 Certifi ==2026.1.4 \ 65 html-webpack-plugin ^5.6.6 65 mini-css-extract-plugin ^2.10.0 66 trove-classifiers ==2026.1.14.14 \ 68 Ristretto v2.4.2 68 installer ==0.7.0 \ 69 pyOpenSSL (>=26.3.0,<27.0.0) 70 VCR.py * 71 css-loader ^7.1.3 71 fastjsonschema ==2.21.2 \ 71 pyproject-hooks ==1.2.0 \ 71 python-semver >=3.0 72 Turbo 8.0.23 72 go-humanize v1.0.1 outdated 73 webpack-bundle-analyzer ^5.0.0 75 lipgloss v1.1.0 76 Bubbles v1.0.0 76 python-zstandard ==0.25.0 \ 77 pycparser ==3.0 \ 78 Lit 3.3.3 79 CacheControl ==0.14.4 \ 79 cffi ==2.0.0 \ 79 tomlkit ==0.14.0 \ 80 attrs >=23.2 80 idna ==3.15 \ 80 sass-loader ^17.0.0 81 Charset Normalizer ==3.4.4 \ 81 Flask ==3.1.3 81 Requests ==2.33.0 \ 82 Bubble Tea v1.3.10 83 python-markdown2 ==2.5.5 84 cryptography ==48.0.1 \ 85 packaging ==26.0 \ 85 pygit2 ==1.19.1 outdated 86 AnyIO ==4.12.1 \ 86 RapidFuzz ==3.14.3 \ 87 more-itertools ==10.8.0 \ 88 Gunicorn ==26.0.0 outdated 88 platformdirs ==4.5.1 \ 89 build ==1.4.0 \ 89 filelock ==3.20.3 \ 90 fake-gcs-server v1.54.0 outdated 90 hypothesis * 90 jsonschema ==4.26.0 91 Google API Python Client ==2.192.0 outdated 91 Poetry ==2.3.4 \ 91 Sass ^1.97.3 91 compress v1.19.0 outdated 91 go-redis v9.21.0 outdated 92 dulwich ==1.2.5 \ 93 go-git v5.19.1 outdated 93 go-git v6.0.0-alpha.4 93 urllib3 ==2.7.0 \ 93 webpack-cli ^7.0.0 94 Werkzeug ==3.1.8 outdated 94 grpc-gateway v2.29.0 outdated 94 redis-py ==6.4.0 outdated 94 webpack-dev-server ^6.0.0 95 Pylint * 97 gRPC Python (grpcio) ==1.75.0 outdated 97 gRPC Python Health Checking ==1.75.0 outdated 97 gRPC Python Health Checking * 97 webpack ^5.105.4 98 google-auth ==2.55.2 outdated 98 google-auth ==0.3.0 outdated 98 google-auth ==3.13.0 outdated 98 google-auth ==2.4.0 outdated 98 google-auth ==2.35.0 outdated 98 google-auth (==2.26.0) 98 google-auth ==3.12.0 outdated

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers