Dependency Vulnerability Scanner with OSV
Use a lockfile with resolved versions; manifest ranges are not resolved. Package names, versions and ecosystems are sent to OSV; missing advisories do not establish safety.
Use a lockfile with resolved versions; manifest ranges are not resolved. Package names, versions and ecosystems are sent to OSV; missing advisories do not establish safety.
Dependency Vulnerability Scanner belongs to the web operation tools on KivTools. The workbench above handles the whole job on one screen: files chosen from your device, then a text result you can copy.
The conversion runs inside the page with browser JavaScript. Nothing you enter is uploaded, the tool keeps working offline, and it is safe for data you are not allowed to send to a third party.
Web infrastructure problems are usually visible only from the outside: what DNS answers, which headers a server returns, whether a redirect loops or a certificate covers the hostname. These tools inspect a live endpoint from the public internet and report what an ordinary client would see.
A single probe is a snapshot, not a guarantee. GeoDNS, CDNs and caches can answer differently from another network, so compare results from a second vantage point before changing production settings.
Browsers, desktop tools and command-line utilities should agree on the result; a mismatch usually means a different encoding, locale or version. Reproduce the finding with the platform’s own tools (dig, curl -I, openssl s_client) before you act on it; the numbers should agree.
Timeouts and blocked ports often come from firewalls or ISPs on the path, not from the target service itself, which is why an external check is a useful second opinion. Keep a copy of the input while you experiment, so a wrong setting never destroys the source.
Takes package manifests, lockfiles, requirements.txt, Maven XML, or CycloneDX files (.json, .lock, .txt, .xml) and returns OSV vulnerability findings for up to 100 exact versioned dependencies.
Check a Python requirements.txt before release; audit a CycloneDX SBOM during CI; verify a suspicious npm lockfile entry after a supply-chain alert.
The manifest is parsed in the browser, then exact package ecosystem, name, and version values are sent to OSV.dev for vulnerability lookup.
Supports only exact version pins, not ranges or wildcards; limited to 100 packages per scan.
Yes. Every tool on KivTools is free, needs no account and has no usage quota. There is no paid tier hiding behind the workbench, and no email address is required to use the result.
Inside your browser. The page loads a script once and the conversion happens on your machine, which is also why the tool still works when the network drops.
Takes package manifests, lockfiles, requirements.txt, Maven XML, or CycloneDX files (.json, .lock, .txt, .xml) and returns OSV vulnerability findings for up to 100 exact versioned dependencies. Large inputs are usually handled without trouble, but extremely large ones are better processed in a local command-line tool.
Configuration is only real once it is served: verify the header or rule on the live response. Compare a small known-good sample first when the output feeds an automated pipeline.
The output is yours: no watermark, no licence tag, no attribution requirement. Check the underlying format or library licence when the result ships in a product.
The page works in any modern mobile browser, and the layout collapses to a single column on small screens. Local tools keep working offline once the page has loaded.