
70% of the code in your app wasnât written by you.
Spin up a basic Python web app and youâve already pulled in a web framework, a templating engine, an HTTP library and whatever else those depend on.
And every so often, someone finds a hole in one of them.
So how do you know if the stuff youâve pulled in is safe? You scan it.
Today weâre doing exactly that with OSV-Scanner, a free, open source tool from Google. This one is probably a smidgen too long for your inbox, so follow along in your browser.
By the end of this newsletter, youâll:
â Understand the moving parts: dependencies, lockfiles, advisories, CVEs and the OSV database
â Install OSV-Scanner on Windows (WSL), macOS or Linux
â Scan a deliberately vulnerable app, read every column of the results, fix it and prove itâs fixed
â Know exactly where this fits in a proper DevSecOps pipeline (and on your CV)
Letâs get into itâŠ
Before we install anything, stay with me here. A scanner is only useful if you understand what itâs comparing. There are five pieces to get your head around, and none of them are scary.
Dependencies: Code your project uses but didnât write. Think of baking a cake with shop bought flour. Youâre responsible for the cake, but you didnât mill the flour. If the flour factory had a recall, your cake has a problem too.
Direct vs transitive: You install Flask. Flask brings Jinja2. Flask is a direct dependency, Jinja2 is a transitive one (a dependency of a dependency). Most of the scary stuff hides in that second group, because you never chose it.
Manifests and lockfiles: A manifest is your shopping list (requirements.txt, package.json). A lockfile is the receipt, the exact versions that actually got installed (package-lock.json, poetry.lock). Scanners love lockfiles because exact versions mean exact answers.
Advisories and CVEs: When someone finds a hole in a package, it gets written up as an advisory (whatâs broken, which versions, what fixes it). A CVE is just a reference number for that bug, like a case number. Youâll see the same bug under several names, which trips everyone up at first.
OSV.dev: A free, open vulnerability database run by Google. It pulls advisories from lots of open sources (GitHub, the Python Packaging Authority, RustSec, Linux distros and more) into one format that a machine can read without guessing.
And OSV-Scanner is the bit in the middle. It reads your shopping list, asks OSV.dev âanything known about these exact versions?â and tells you what comes back.
Side Note: One bug can have three names
Different databases give the same bug their own ID. Pythonâs database calls it one thing, GitHub calls it another, and the global CVE system gives it a third.
OSV calls these aliases and groups them together, so youâre fixing one bug, not three. When a colleague says âhave you patched CVE-2018-1000656?â and your scanner says PYSEC-2018-66, you now know youâre talking about the same thing.
That kind of detail makes you sound like youâve done this before đ Fake it till you make it and so on⊠No, really.
As usual, I reserve the Projects for community membersâŠCome join the fun! đ





