compare
OSV-Scanner vs Trivy
The same facts for both, read from GitHub every night, and the relation a person reviewed.
| Fact | OSV-Scanner | Trivy |
|---|---|---|
| Language | Go | Go |
| Licence | Apache-2.0 | Apache-2.0 |
| Stars | 11k | 38k |
| Latest | v2.6.0 | v0.75.0 |
| Last push | 2026-10-05 | 2026-10-06 |
| Release cadence | about 35 days between releases | about 23 days between releases |
| Active contributors | 19 commit authors on the default branch in the last 90 days | not counted |
| Flags | none | none |
How they relate
Both replace Snyk. Alternatives to Snyk →
PartialOSV-ScannerDependency and container image scanning against OSV.dev, with guided remediation for npm and Maven.
PartialTrivyScans dependencies, container images, infrastructure as code and secrets from the CLI or CI; no hosted dashboard or fix pull requests.
OSV-Scanner
- v2.6.02026-09-14Feature #2888 Publish multi-arch (linux/arm64) image for osv-scanner-action.
- v2.5.12026-08-17Preserve package namespaces when querying osv.dev API (fixes #2978).
- v2.5.02026-08-07Full OSV-Scalibr pipeline: Migrated scanning, filtering, and matching in osv-scanner to use osv-scalibr end-to-end, so…
- v2.4.02026-06-18Feature #2815 Add support for the CycloneDX 1.7 specification (bumps cyclonedx-go to v0.11.0).
- v2.3.82026-05-08Fix installation issues with go install due to dependency conflicts (downgrade containerd/cgroups/v3, moby/buildkit and…
OSV-Scanner
✓ signed The latest release, v2.6.0, carries a signature GitHub verified.
Loading the security report
Trivy
✓ signed The latest release, v0.75.0, carries a signature GitHub verified.
Loading the security report