The Year in Review
2025 has been an eventful year for OSV, marked by significant expansion, infrastructure improvements, and continued community growth across all our projects.
Source: Open Source Vulnerabilities Database · July 23, 2026 at 11:07 PM · AI-assisted report
KUALA LUMPUR, 24 JULY 2026 —
Listen to this article
DomainFork Audio · read aloud
Headline: The Year in Review Lead: 2025 has been an eventful year for OSV, marked by significant expansion, infrastructure improvements, and continued community growth across all our projects. Body: 2025 has been an eventful year for OSV, marked by significant expansion, infrastructure improvements, and continued community growth across all our projects.
We welcomed 11 new data providers, and 11 new ecosystems. Every new data provider helps us improve vulnerability coverage and matching for the open source community.
We’ve also begun to diversify our CVE matching data by ingesting directly from the CVE Program’s CVEList as well as the NVD, allowing for more accurate vulnerable ranges. Look out for an upcoming blog post going deeper into this project.
Following the introduction of the upstream field last year, we have separated the Debian and Alpine vulnerability data, which were previously merged with the main NVD CVE record-into distinct records, each with its own prefix. This ensures records only apply to the environments they exist in, significantly reducing false positives–such as preventing Debian vulnerability alerts from appearing on Alpine systems.
Behind the scenes, we’ve focused on ensuring OSV.dev remains fast and reliable.
Early last year, we announced the significant improvements on the performance and reliability of the OSV.dev API . By implementing a new database indexing strategy, we made API queries up to 5 times faster. This is a substantial improvement, with the 95th percentile latency for batch queries dropping from ~10 seconds to ~3 seconds. This speed increase unlocks new possibilities for real-time CI/CD integration, allowing developers to scan against the API without hitting timeout thresholds. Following these enhancements, we have revised our API SLOs to reflect this new, higher standard of performance.
Vanir signatures are now available through OSV.dev. To enhance Vanir’s coverage of open-source libraries, the OSV.dev worker is now responsible for generating and processing Vanir signatures for all vulnerabilities with GIT affected ranges. In addition, a new public data dump is now available, which provides a JSON file listing all GIT vulnerabilities that have Vanir signatures. This file is designed to simplify the use of Vanir’s offline directory scanner.
On the data quality front, we launched an experimental OSV linter to help maintain high consistency across all incoming vulnerability data. This tool checks for consistency beyond schema validation, ensuring high-quality, usable vulnerability data. It allows OSV record creators to integrate these essential quality checks into their workflows, leading to more accurate and immediately useful information.
This standardization allowed us to successfully deprecate manual bindings across the entire OSV ecosystem. For the open-source community, this eliminates the risk of inconsistencies between protocol definitions and language bindings, while removing the need for tedious manual data conversion.
Notably, the OSV-Scanner GitHub Action has been adopted by over 1600 GitHub repositories , demonstrating its value to the developer community.
Our tooling (OSV-Scanner and OSV-Scalibr) continues to evolve with a focus on developer experience and accuracy. Key updates last year include:
We’re already looking forward to the year ahead with ambitious goals to continue improving OSV. Source: Open Source Vulnerabilities Database Published: 2026-01-13T00:00:00.000Z Region: OSINT Topic: Economy (AI-assisted rewrite, based on the original source)
Malaysia Impact
Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.