google/osv.dev

Python 2.5k stars

Open source vulnerability DB and triage service.

✓ Synced 3h ago Share on X →
README badge: [![ngmi](https://ngmi.review/badge/google/osv.dev.svg)](https://ngmi.review/repo/google/osv.dev)
3.6k Merged PRs
2 days Avg Merge Time
0m Fastest PR
4 months Slowest PR
#652 Global Speed Rank

Trends Over Time

Monthly aggregates for this repo. The gap between average and median shows how much outliers are skewing the data.

PR size over time (lines changed)
Review time over time (hrs)
Changes requested rate over time (%)
Merged PRs per month

PR Size Analysis

Lines changed (additions + deletions) vs review outcomes. Re-sync to populate data for older PRs.

PRs by size
Avg review time (hrs)
Clean approval rate (%)

Top Reviewers

Recent Merged PRs

# Title Author Time Reviews Blocks
#4836 chore(deps): lock file maintenance @renovate-bot 6 days 1
#4728 feat(gitter): git commit graph and patch ID caching @Ly-Joey 21 days 22
#4876 fix(vulnfeeds): Cache patch @jess-lowe 18m 2
#4875 chore: fix important security vuln in opentelemetry dependency @another-rex 7m 1
#4873 test: update apitester snapshots @osv-robot 6.8h 1
#4871 docs: update CONTRIBUTING.md to split frontend/backend and add emulator info @jess-lowe 20.5h 3
#4805 test: update apitester snapshots @osv-robot 10 days 1
#4863 feat(logger): Wrapper to extract and log context @Ly-Joey 2 days 2
#4870 fix: experiment with gcloud auth token command @Ly-Joey 4m 1
#4855 fix: attach error reporting directly to logs; sourceLocation @michaelkedar 3 days 1
#4818 docs: add instructions for running the documentation site locally @cuixq 6 days 5
#4868 fix(ui): stop forcing the webpack vendor chunk output path @tymzd 20.2h 2
#4867 chore(deps-dev): bump ajv from 6.12.6 to 6.14.0 in /gcp/website/frontend3 in the npm_and_yarn group across 1 directory @dependabot 21.8h 1
#4859 fix(deps): update dependency flask to v3.1.3 [security] @renovate-bot 12m 2
#4860 fix(deps): update dependency werkzeug to v3.1.6 [security] @renovate-bot 4m 1
#4857 chore(deps-dev): bump nokogiri from 1.18.10 to 1.19.1 in /docs in the bundler group across 1 directory @dependabot 22m 1
#4841 fix(ui): prevent severity CVSS vector strings from overflowing viewport @ashmod 2 days 1
#4856 fix(linter): redirect linter if on prod to test @jess-lowe 8m 2
#4854 fix(worker): use force_update on gitter clones of source repos @michaelkedar 20.1h 1
#4815 refactor(vulnfeeds): move GitVersionsToCommits to common dir and refactor to output resolved ranges @jess-lowe 2 days 3