Simple Vulnerability Scanner matches CycloneDX and SPDX components against OSV, records exact input receipts, reconciles strict OpenVEX evidence, evaluates baselines and policy, and produces review-ready JSON, HTML, and SARIF reports.
The capture below uses SVS v0.3.0 and the bundled CycloneDX sample. Advisory counts can change as OSV records evolve.
Captured 3 September 2026 from a successful scan.
SVS keeps skipped components visible, follows per-query OSV pagination, aborts incomplete enrichment, and recommends a fixed version only when the advisory data proves it.