Built something? We create video reels & spotlights for GitHub projects.Promote your project →
google
Home / Go / osv-scalibr

google/osv-scalibr

OSV-SCALIBR: A library for Software Composition Analysis

Go ◇ developer-tools Apache-2.0
★646STARS
⑂203FORKS
!309ISSUES
🏆#3,241GLOBAL RANK
🔥1DAYS TRENDING
🚀
Maintainer Growth Kit for osv-scalibr

Claim this project, add your verified backlink badge to your README, and download milestone cards.

Claim Repo

Star History

Continuous Observations
Interactive star growth chart for google/osv-scalibr
CSV

Momentum

+16

STARS · LAST 30 DAYS

1

PER DAY

#343

MOST-STARRED Go

Window7 days30 days90 days
Stars gained+7+16+90
Per day111
Forks gained+1+4+10

osv-scalibr gained 16 stars in the last 30 days, about 1 a day, and now has 646. It is about 2 years old and has averaged roughly 323 stars a year. It ranks #343 among Go repositories and #3,241 across all languages on GitHubRepo.

Trending Record

osv-scalibr has maintained a continuous presence across global trending indexes, peaking at #3193. Below is the 30-day activity profile:

💡 Overview

osv-scalibr is an open-source project written in Go: OSV-SCALIBR: A library for Software Composition Analysis.

Engineered for speed, consistency, and developer ease, it solves common hurdles in Go. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.

⚡ Key Features

1

Optimized execution pipeline written in Go for predictable speed.

2

Zero-friction configuration with comprehensive sensible defaults out of the box.

3

Cross-platform runtime support across Linux, macOS, and Windows environments.

4

Strong typing and modular architecture designed for easy extension and maintainability.

5

Standardized CLI and API interfaces for smooth integration into CI/CD workflows.

6

Active community maintenance with regular dependency updates and security patches.

📥 Installation

terminal
$ go install github.com/google/osv-scalibr@latest

⚙ System Requirements

Platforms

  • • macOS
  • • Linux
  • • Windows

Runtime & Dependencies

Go >= 1.21 runtime environment

Architecture

x86_64, ARM64 (Apple Silicon & Graviton)

🧠 How It Works

osv-scalibr coordinates its core functionality through a modular Go pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.

🎯 Production Use Cases

Production System Integration

Embed osv-scalibr into Go backend services to handle core application logic.

CI/CD Automated Pipelines

Run automated validation, builds, and integration suites during deployments.

Developer Tooling & Workflows

Accelerate developer onboarding with pre-configured project utilities.

Open Source Extension

Fork and customize internal modules under the repository's open Apache-2.0 license.

🚀 Getting Started

1

Install osv-scalibr using your package manager: `go install github.com/google/osv-scalibr@latest`

2

Initialize your project workspace or configuration file for osv-scalibr.

3

Import osv-scalibr into your codebase or invoke it directly from your terminal.

4

Execute your test suite or run `osv-scalibr --help` to verify successful setup.

👍 Strengths

Active community backing with 646 GitHub stars and verified adoption.
Permissive open-source distribution under the Apache-2.0 license.
Built in Go for high execution speed and developer familiarity.
Cross-platform compatibility across modern Linux, macOS, and Windows environments.
Clean modular design allowing flexible configuration and pipeline integration.

⚠️ Considerations

Requires familiarity with Go and modern CLI workflows.
Ecosystem extensions may require manual configuration depending on environment constraints.
Active development roadmap means breaking API changes may occur across major versions.

⇄ Alternatives & Direct Competitors

A
avelino/awesome-go ★ 185.9K Go

A curated list of awesome Go frameworks, libraries and software

Compare ↗
O
ollama/ollama ★ 181.8K Go

Get up and running with Kimi, GLM, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models.

Compare ↗
G
golang/go ★ 139.1K Go

The Go programming language

Compare ↗
K
kubernetes/kubernetes ★ 128K Go

Production-Grade Container Scheduling and Management

Compare ↗

👥 Who Should Use This

Developers and engineering teams building with Go, seeking reliable, tested, and actively maintained tooling for production workloads.

🏆 Nearby in the Rankings

google/osv-scalibr is currently ranked #3,241 by stars across every repository tracked on GitHubRepo. These are adjacent projects:

RankRepositoryLanguageStarsAction
#3,234 pablopunk/SwiftShift Swift ★ 649 Compare ↗
#3,237 tetherto/qvac TypeScript ★ 648 Compare ↗
#3,237 androoAGI/starnet JavaScript ★ 648 Compare ↗
#3,239 smallnest/ringbuffer Go ★ 647 Compare ↗
#3,239 GSTJ/magic-modal TypeScript ★ 647 Compare ↗
#3,241 google/osv-scalibr This Project Go ★ 646
#3,241 recurly/recurly-js JavaScript ★ 646 Compare ↗
#3,241 hackthedev/dcts-shipping JavaScript ★ 646 Compare ↗
#3,241 dietrichmax/colota TypeScript ★ 646 Compare ↗
#3,245 patrickjaja/claude-desktop-extra JavaScript ★ 645 Compare ↗
#3,246 decentralized-identity/universal-resolver Java ★ 644 Compare ↗

Frequently Asked Questions

What does osv-scalibr do? +

OSV-SCALIBR: A library for Software Composition Analysis

What language is osv-scalibr written in? +

The primary language is Go. Topics include: software.

Is osv-scalibr actively maintained? +

Yes, the last recorded push was on Sep 28, 2026 with 309 open issues being tracked.

How many stars does osv-scalibr have? +

osv-scalibr has 646 stars and 203 forks on GitHub.

How does osv-scalibr rank among GitHub repositories? +

With 646 stars, google/osv-scalibr is ranked #3,241 globally across all repositories tracked on GitHubRepo and #343 among Go projects.

What license is osv-scalibr distributed under? +

The repository reports a Apache-2.0 license. Always verify the repository LICENSE file for legal terms.

From our network
FOR MAINTAINERS

Built something? Put it in front of millions of developers.

We make a short reel about your project and post it across YouTube, Instagram, Threads, and X. Send a link, we do the rest.