Vulnerability detection now covers ecosystem-native OSV advisories

Packages from Debian, Alpine, PyPI, and other ecosystems that use native version ranges are now matched against a broader set of OSV advisories, building on existing coverage for SemVer-based ranges.

Users with active vulnerability policies that use the OSV.dev dataset may see more policy matches than before. This is expected: your policies are now being evaluated against a more complete set of advisories. It's broader coverage, not noise.

Ecosystems with improved coverage:

  • AlmaLinux
  • Alpine
  • Chainguard
  • CRAN
  • Debian
  • NuGet
  • openSUSE
  • Packagist
  • Pub
  • PyPI
  • Red Hat
  • Rocky Linux
  • RubyGems
  • SUSE
  • Ubuntu
  • Wolfi

Visit our documentation for more information on how to access the OSV.dev dataset to create your vulnerability policies.

Keep up to date with our monthly product bulletin