{"uid":"cap_XkRDmEdCKds2qPfrBFJMa","slug":"dependency-risk-batch-vulnerability-check-32d47308","name":"Dependency Risk Batch Vulnerability Check","description":"Batch dependency vulnerability check — check ordered exact package versions in OSV with deduplicated CVE enrichment, explicit completeness, and CISA KEV known-exploited signals.","url":"https://dependency-risk.use.x402atlas.com/batch","method":"POST","headers":{},"bodySchema":null,"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_JzziR2eSZpNcDBockKZAU","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Batch-checks multiple exact open-source package versions against OSV with deduplicated CVE enrichment, completeness guarantees, and CISA KEV known-exploited signals.","exampleAgentPrompt":"Can you batch-check these npm packages for known vulnerabilities, CVEs, and whether any are on the CISA known-exploited list: lodash@4.17.20, express@4.18.1, and axios@0.21.1?","exampleUseCases":[{"title":"Pre-deployment dependency security audit","prompt":"Before I push this release, can you scan all these exact package versions for known CVEs and flag any that are in the CISA known-exploited vulnerabilities list: django@3.2.12, pillow@9.0.0, and requests@2.27.0?"},{"title":"CI pipeline vulnerability gate check","prompt":"I need to audit my project's dependencies as part of CI — can you check lodash@4.17.11, minimist@1.2.5, and node-fetch@2.6.1 against OSV and tell me if any have critical CVEs or confirmed exploits in the wild?"},{"title":"Open source license and risk triage","prompt":"We're onboarding a new vendor's software and want to verify their dependencies are clean — please batch-check spring-core@5.3.18, log4j-core@2.14.1, and jackson-databind@2.13.0 for OSV vulnerabilities and CISA KEV signals."}],"resultDescription":"Returns a structured list of vulnerability results for each submitted package, including matched CVE identifiers, CVSS severity scores, OSV advisory details, affected version ranges, deduplication across overlapping advisories, explicit completeness flags indicating whether the check was exhaustive, and CISA KEV signals flagging packages with actively exploited known vulnerabilities.","failureModes":["Invalid or unrecognized package ecosystem returns empty or error result for that entry","Package version not found in OSV returns no vulnerabilities but completeness flag may be false","Malformed purl or version string causes validation error for affected entries","Batch size exceeds API limits resulting in a 413 or truncated response","Network timeout for large batches","OSV upstream unavailability causing partial or degraded results"],"whenToPreferThis":"Use this endpoint when you need to check multiple packages in a single call rather than querying one at a time — it is more efficient for auditing lockfiles, dependency lists, or SBOMs with many components. It is especially valuable when you need CISA KEV enrichment alongside OSV data in one response, or when completeness guarantees and deduplication of overlapping CVEs across advisories are important for downstream risk decisions.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:31:59.885Z","isFirstParty":false}