Google has announced a new tool designed to help identify vulnerabilities in open source software.
The OSV-Scanner is described as a frontend to the existing OSV (open source vulnerabilities) database and one of the aims is to alert developers to security issues in the code their projects depend on.