Skip to content
Roster

Roster Data · Lookup

Dependency vulnerability check — any package version (OSV, live)

Check whether a specific package version (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist…) has known vulnerabilities or is a known malicious package. Returns advisory ids, summaries, severity and fixed versions. Live query to OSV.dev. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.

What you get

A direct answer to your input as JSON matches, with source attribution.

Answer one question · inline JSON

Price
0.01 USDC
Freshness
Live
Refresh
live
p95
8000 ms

Source & license

Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.

Schema

idstringOSV id (GHSA-…, PYSEC-…, MAL-…).
kindstringvulnerability or malicious-package.
packagesstringAffected package names, semicolon-separated.
summarystringShort summary.
severitystringDatabase severity (LOW…CRITICAL) when given.
cvss_vectorstringCVSS vector when given.
aliasesstringCVE and other aliases.
introducedstringIntroduced versions.
fixedstringFixed versions.
published_atdatetimePublished.
modified_atdatetimeLast modified.
withdrawnbooleanAdvisory withdrawn.
urlstringosv.dev page.

Buy from code

curl -X POST https://roster.network/roster-api/v1/need/buy \
  -H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
  -d '{"listingId":"cap_12941cd7c931ae7d","input":{"ecosystem":"npm","name":"lodash","version":"4.17.15"}}'

// SDK
const { matches } = await roster.need("Dependency vulnerability check — any package version (OSV, l");
const bought = await roster.buy({ listingId: "cap_12941cd7c931ae7d" });