{"uid":"cap_dzGJU9xtnCUzjzK0d_DHM","slug":"sitesignal-osv-package-vulnerabilities-7022798c","name":"SiteSignal OSV Package Vulnerabilities","description":"Return bounded OSV vulnerability records for one exact package ecosystem, name, and version.","url":"https://phases-prot-shine-royal.trycloudflare.com/x402/osv-vulnerabilities","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["ecosystem","package","version"],"properties":{"package":{"type":"string","maxLength":255,"minLength":1},"version":{"type":"string","maxLength":128,"minLength":1},"ecosystem":{"enum":["npm","PyPI","Maven","Go","crates.io"],"type":"string"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.015","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.015/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_8slsIGFX1gTVpfYTyboPI","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.015","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns bounded OSV (Open Source Vulnerabilities) records for a specific package version in a given ecosystem (npm, PyPI, Maven, Go, or crates.io).","exampleAgentPrompt":"Check the OSV vulnerability database for lodash version 4.17.20 in the npm ecosystem and tell me if there are any known security issues.","exampleUseCases":[{"title":"Pre-deployment dependency security audit","prompt":"Before we ship this release, can you check if express version 4.18.2 on npm has any known vulnerabilities in the OSV database?"},{"title":"Python library CVE check","prompt":"Look up whether requests version 2.28.0 in PyPI has any reported security vulnerabilities — I want to know before adding it as a dependency."},{"title":"Rust crate safety verification","prompt":"Is the serde version 1.0.152 crate on crates.io flagged for any known vulnerabilities in OSV? We're about to lock this into our Cargo.toml."}],"resultDescription":"A bounded set of OSV vulnerability records matching the specified package ecosystem, name, and version. Each record typically includes vulnerability IDs (e.g. CVE, GHSA identifiers), affected version ranges, severity details, and source links from the OSV database.","failureModes":["Package not found in the specified ecosystem returns empty vulnerability list","Invalid or unsupported ecosystem value returns a validation error","Malformed version string may return no results or an error","Network timeouts from upstream OSV API may cause failure","Rate limiting or payment failure (x402) blocks the request"],"whenToPreferThis":"Choose this endpoint when you need a quick, bounded vulnerability lookup for a single exact package version against the OSV database — ideal for CI/CD pipelines, dependency audits, or pre-deployment checks. It supports the most common ecosystems (npm, PyPI, Maven, Go, crates.io). Prefer this over broader SCA (software composition analysis) tools when you only need OSV data for one package at a time without a full project scan.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T17:29:21.680Z","isFirstParty":false}