Source-backed vulnerability findings
The scanner parses supported repository manifests and queries OSV. Findings originate in source data, not model-generated advisory prose. Unsupported inputs and incomplete coverage remain limitations.
Read the scanner implementation