Roster Data · Lookup
Dependency vulnerability check — any package version (OSV, live)
Check whether a specific package version (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist…) has known vulnerabilities or is a known malicious package. Returns advisory ids, summaries, severity and fixed versions. Live query to OSV.dev. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.
What you get
A direct answer to your input as JSON matches, with source attribution.
Answer one question · inline JSON
- Price
- 0.01 USDC
- Freshness
- Live
- Refresh
- live
- p95
- 8000 ms
Source & license
- OSV — Open Source Vulnerabilities · CC-BY-4.0
Source: OSV.dev (CC BY 4.0); individual advisories carry their upstream database attribution.
Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.
Schema
| id | string | OSV id (GHSA-…, PYSEC-…, MAL-…). |
| kind | string | vulnerability or malicious-package. |
| packages | string | Affected package names, semicolon-separated. |
| summary | string | Short summary. |
| severity | string | Database severity (LOW…CRITICAL) when given. |
| cvss_vector | string | CVSS vector when given. |
| aliases | string | CVE and other aliases. |
| introduced | string | Introduced versions. |
| fixed | string | Fixed versions. |
| published_at | datetime | Published. |
| modified_at | datetime | Last modified. |
| withdrawn | boolean | Advisory withdrawn. |
| url | string | osv.dev page. |
Buy from code
curl -X POST https://roster.network/roster-api/v1/need/buy \
-H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
-d '{"listingId":"cap_12941cd7c931ae7d","input":{"ecosystem":"npm","name":"lodash","version":"4.17.15"}}'
// SDK
const { matches } = await roster.need("Dependency vulnerability check — any package version (OSV, l");
const bought = await roster.buy({ listingId: "cap_12941cd7c931ae7d" });