{"uid":"cap_-9SFeBVm4BreM7ZZP3dnI","slug":"dependency-risk-single-package-vulnerability-check-f74ec38e","name":"Dependency Risk Single Package Vulnerability Check","description":"Package vulnerability check — check one exact open-source dependency version or purl against OSV, enrich CVE matches with CISA KEV known-exploited signals, and report fixes, severity, and provenance.","url":"https://dependency-risk.use.x402atlas.com/package","method":"POST","headers":{},"bodySchema":null,"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_MHj1DA5oCNU-SEpZDxYfs","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks one open-source package version or purl against OSV, enriches CVE matches with CISA KEV known-exploited signals, and returns fix recommendations, severity scores, and provenance.","exampleAgentPrompt":"Can you check whether lodash version 4.17.20 on npm has any known vulnerabilities, including whether any CVEs are in the CISA KEV known-exploited list, and tell me what version I should upgrade to?","exampleUseCases":[{"title":"Pre-release dependency safety gate","prompt":"Before we cut this release, check if requests==2.27.1 on PyPI has any known CVEs, especially ones flagged as actively exploited by CISA, and tell me if there's a safe version to upgrade to."},{"title":"Supply chain audit for a suspect package","prompt":"I just found log4j 2.14.1 in our Java app — can you look it up in OSV and tell me the full vulnerability picture, including severity and whether it's on the CISA known-exploited list?"},{"title":"Automated PR security check","prompt":"This pull request adds express@4.18.1 as a dependency — can you check it for vulnerabilities in OSV and let me know the severity and whether any findings are actively being exploited in the wild?"}],"resultDescription":"Returns a structured report for the queried package version including: matched OSV advisory IDs, CVE identifiers, CVSS severity scores, whether each CVE appears in the CISA KEV known-exploited catalog, recommended fix/patched versions, and provenance metadata about each vulnerability finding.","failureModes":["Unknown or misspelled package name returns no matches rather than an error","Unsupported ecosystem or malformed purl returns a validation error","Package version not found in OSV returns empty vulnerability list (not necessarily safe)","Network timeout to OSV or CISA KEV upstream returns a service error","Very new CVEs not yet indexed in OSV may be missed"],"whenToPreferThis":"Use this endpoint when you need to check a single, precisely identified package version (by name+version or purl) for vulnerabilities with CISA KEV enrichment — ideal for per-dependency CI gates, PR checks, or on-demand advisory lookups. Choose the batch sibling endpoint when scanning multiple dependencies at once, and the SBOM sibling for full CycloneDX bill-of-materials analysis.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:38:09.159Z","isFirstParty":false}