{"uid":"cap_ji04m51luPTygTm9ELhFM","slug":"github-security-advisories-for-npm-ghsa-npm-changes-9ce0f80b","name":"GitHub Security Advisories for npm (GHSA NPM Changes)","description":"New security vulnerabilities and CVEs affecting npm packages published since a timestamp (GitHub's reviewed advisory database) — each with its CVE ID, CVSS/severity score, affected package names, and a link. Answers \"did a dependency I use get a new CVE or vulnerability I should patch?\"","url":"https://oracles-production.up.railway.app/v1/ghsa-npm/changes","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"limit":{"type":"integer","maximum":500,"minimum":1},"since":{"type":"string","format":"date-time","description":"Only changes detected after this ISO-8601 instant"},"min_significance":{"type":"integer","maximum":10,"minimum":1,"description":"Keep only changes scored at least this"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"count":{"type":"integer"},"source":{"type":"string"},"changes":{"type":"array","items":{"type":"object","properties":{"type":{"type":"string"},"title":{"type":"string"},"detail":{"type":"object"},"summary":{"type":"string"},"entityId":{"type":"string"},"sourceUrl":{"type":["string","null"],"description":"Primary-source link for verification"},"detectedAt":{"type":"string","format":"date-time"},"significance":{"type":"integer","maximum":10,"minimum":1},"effectiveDate":{"type":["string","null"]}}}}}}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Ao3A87x2dDz2MTRSX0yhU","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns reviewed GitHub security advisories for npm packages published since a given timestamp, scored by severity (1-10), with affected package details and source links.","exampleAgentPrompt":"Pull all GitHub security advisories for npm packages published since 2025-01-01T00:00:00Z with a severity score of at least 7, limit to 50 results.","exampleUseCases":null,"resultDescription":"Returns a JSON object containing a count of matching advisories and an array of change records, each with a title, summary, GHSA entity ID, severity significance score (1-10), detection timestamp, effective date, affected package details, and a direct source URL to the advisory on GitHub.","failureModes":["Invalid ISO-8601 timestamp in 'since' parameter returns a 400 error","'limit' value outside 1-500 range returns validation error","'min_significance' outside 1-10 range returns validation error","No advisories matching the criteria returns an empty changes array with count 0","Payment not included or insufficient USDC balance returns 402 Payment Required","Service downtime or upstream GitHub Advisory Database unavailability returns 503"],"whenToPreferThis":"Use this endpoint when you need to continuously monitor or poll for new npm package security advisories from the GitHub Advisory Database, especially when you need severity-scored results filterable by time window and minimum significance. Prefer this over generic CVE feeds when you specifically care about the npm ecosystem and want GHSA-curated, reviewed advisories with direct source links for verification.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:54:13.616Z","isFirstParty":false}