Uploaded May 2026 | Updated September 2026, 4 hours ago
Jess Lowe (Google, AU), Rex Pan (Google, AU)
A scalable "alert on artifact" workflow for vulnerability management requires precise and accurate data on which code versions are affected. This is already challenging for linear versioning but becomes significantly more difficult when dealing with non-linear Git graphs. What exactly do "introduced" and "fixed" commits communicate about the vulnerable commits? How do intermediate branches, merges, and forks complicate this picture? We will explore all scenarios encountered while developing the OSV database, offering real-world examples and the corresponding solutions implemented in the OSV-Schema. Attendees will learn how these solutions can help accurately identify vulnerabilities within their dependencies.
---
Jess Lowe is a Software Engineer on the Open Source Vulnerabilities (OSV) project within Google’s Open Source Security Team. Recently, she's been deep in the weeds of bulk CVE conversion, designing the logic and heuristics required to turn ambiguous security records into actionable, machine-readable data.
Rex Pan is a Software Engineer Tech Lead on the Open Source Vulnerabilities (OSV) team and the Google Open Source Security team. His current work concentrates on enhancing developer workflows for addressing and remediating vulnerabilities within their Open Source Software (OSS) dependencies.
Jess Lowe (Google, AU), Rex Pan (Google, AU)
A scalable "alert on artifact" workflow for vulnerability management requires precise and accurate data on which code versions are affected. This is already challenging for linear versioning but becomes significantly more difficult when dealing with non-linear Git graphs. What exactly do "introduced" and "fixed" commits communicate about the vulnerable commits? How do intermediate branches, merges, and forks complicate this picture? We will explore all scenarios encountered while developing the OSV database, offering real-world examples and the corresponding solutions implemented in the OSV-Schema. Attendees will learn how these solutions can help accurately identify vulnerabilities within their dependencies.
---
Jess Lowe is a Software Engineer on the Open Source Vulnerabilities (OSV) project within Google’s Open Source Security Team. Recently, she's been deep in the weeds of bulk CVE conversion, designing the logic and heuristics required to turn ambiguous security records into actionable, machine-readable data.
Rex Pan is a Software Engineer Tech Lead on the Open Source Vulnerabilities (OSV) team and the Google Open Source Security team. His current work concentrates on enhancing developer workflows for addressing and remediating vulnerabilities within their Open Source Software (OSS) dependencies.










