{"uid":"cap_RIN6qsPwPc8B9j4rPxxGX","slug":"sitesignal-osv-package-vulnerabilities-528957db","name":"SiteSignal OSV Package Vulnerabilities","description":"Return bounded OSV vulnerability records for one exact package ecosystem, name, and version.","url":"https://trinity-throw-thursday-gravity.trycloudflare.com/x402/osv-vulnerabilities","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["ecosystem","package","version"],"properties":{"package":{"type":"string","maxLength":255,"minLength":1},"version":{"type":"string","maxLength":128,"minLength":1},"ecosystem":{"enum":["npm","PyPI","Maven","Go","crates.io"],"type":"string"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.015","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.015/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_XCZlBpLfW7I0xbqB465Rz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.015","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns bounded OSV (Open Source Vulnerabilities) vulnerability records for a specific package identified by ecosystem, name, and version.","exampleAgentPrompt":"Can you check the OSV vulnerability database for lodash version 4.17.20 in the npm ecosystem and tell me if there are any known security issues?","exampleUseCases":[{"title":"Pre-deployment dependency audit","prompt":"Before we ship this release, check if express version 4.18.1 in npm has any known vulnerabilities in the OSV database."},{"title":"Python package security review","prompt":"I'm about to add requests 2.28.0 as a dependency — can you look it up in the PyPI ecosystem on the OSV vulnerability database and tell me if it's safe?"},{"title":"Rust crate vulnerability check","prompt":"We're using serde version 1.0.150 from crates.io in our project — please check the OSV records and tell me if there are any reported security vulnerabilities."}],"resultDescription":"A bounded set of OSV vulnerability records for the specified package, including vulnerability IDs (e.g. CVE, GHSA), severity ratings, affected version ranges, descriptions, and references to security advisories or patches.","failureModes":["Unknown or misspelled package name returns empty results rather than an error","Unsupported ecosystem (outside npm, PyPI, Maven, Go, crates.io) returns validation error","Malformed or non-existent version string may return empty results","Rate limiting or upstream OSV API unavailability causes request failure","Network timeout from Cloudflare tunnel proxy"],"whenToPreferThis":"Use this endpoint when you need a quick, per-package vulnerability lookup against the OSV database for a specific ecosystem, name, and version combination. Prefer it over general web searches when you need structured, machine-readable vulnerability data from a canonical source. It covers the five most common ecosystems (npm, PyPI, Maven, Go, crates.io) and is ideal for automated dependency audits or pre-deployment security checks.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T09:26:24.087Z","isFirstParty":false}