{"uid":"cap_8nmPLuNJoivKu6qNm-ILI","slug":"deps-dev-package-metadata-lookup-89a28538","name":"deps.dev Package Metadata Lookup","description":"Package intelligence from deps.dev (Google Open Source Insights, data CC-BY 4.0): resolved license list, known advisory ids, source project, GitHub stars and OpenSSF Scorecard overall score. Query: ?system=npm&pkg=react&version=latest (systems: npm, pypi, go, maven, cargo, nuget; version defaults to the registry default release). Refreshed upstream continuously; served with a 6h cache.","url":"https://data.greeneris.io/v1/dev/deps","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["pkg"],"properties":{"pkg":{"type":"string","description":"Package name, e.g. react or @types/node"},"system":{"enum":["npm","pypi","go","maven","cargo","nuget"],"type":"string","default":"npm","description":"Package ecosystem"},"version":{"type":"string","default":"latest","description":"Exact version, or 'latest' for the registry default"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"stars":246457,"source":"deps.dev (Google Open Source Insights), data licensed CC-BY 4.0","system":"npm","package":"react","project":"github.com/facebook/react","version":"19.2.7","licenses":["MIT"],"advisories":[],"is_default":true,"published_at":"2026-06-01T18:00:48Z","scorecard_date":"2026-06-29T00:00:00Z","scorecard_score":6.6}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_x19rtGz5JK4ayU7fzJnvX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches open-source package metadata (version, license, advisories, scorecard, GitHub stars) from deps.dev (Google Open Source Insights) for npm, PyPI, Go, Maven, Cargo, and NuGet packages.","exampleAgentPrompt":"Can you check the latest version of the react npm package, confirm its license, and tell me if there are any known security advisories or its OpenSSF scorecard score?","exampleUseCases":[{"title":"Audit dependencies for license compliance","prompt":"I need to audit our project dependencies across npm and PyPI to make sure we're not using anything with incompatible licenses like GPL. Can you pull the license info for our key packages and flag any potential issues?"},{"title":"Screen packages for production safety","prompt":"Before we add this new Go module and that Rust crate to our critical system, can you check if they have any known security advisories and what their OpenSSF scorecard scores are? I want to make sure they're actively maintained."},{"title":"Track open source supply chain health","prompt":"Help me understand the security posture of our main dependencies across all our ecosystems. Can you grab the advisories, scorecards, and GitHub activity metrics for our core npm, PyPI, and Maven packages so we can prioritize remediation?"}],"resultDescription":"A JSON object containing the package name, resolved version, ecosystem, license(s), list of security advisories, OpenSSF scorecard score and date, GitHub stars, whether this is the default/latest version, publication timestamp, and upstream project URL (e.g. github.com/facebook/react).","failureModes":["Package not found in the specified ecosystem — returns 404 or empty result","Invalid ecosystem enum value — request rejected with schema validation error","Version string does not exist for the package — returns error or empty advisories","Payment not made — HTTP 402 returned with machine-readable price quote requiring USDC payment on Base via x402 protocol","Network timeout or upstream deps.dev unavailability"],"whenToPreferThis":"Use this endpoint when you need authoritative, up-to-date open-source package metadata including license compliance, security advisories, and supply-chain scorecard data sourced directly from Google's deps.dev. Prefer this over scraping npm/PyPI registry pages directly when you need a unified multi-ecosystem API with structured JSON output and no API key setup.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:50:21.455Z","isFirstParty":false}