Skip to content
Roster

Roster Data · Feed

npm security advisories & malicious packages feed (OSV)

Rolling 30-day feed of new and updated npm security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.

What you get

The latest items as JSON. Filter with since, q, or limit. Includes attribution.

Recent items · filter by date or text

Price
0.01 USDC
Freshness
Updated 4 h ago
Refresh
every 3 hours
Rows
250 · 103 KB

Source & license

Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.

Sample

idkindpackagessummaryseveritycvss_vectoraliasesintroduced
GHSA-7c34-32v3-j575vulnerabilitypayloadPayload relationship-query authorization bypassMODERATECVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:…CVE-2026-1058520;4.0.0-canary.0
GHSA-8r29-2mp2-pmrwvulnerability@payloadcms/plugin-ecommercePayload Ecommerce has an order confirmation val…HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:…CVE-2026-1058500;4.0.0-canary.0
GHSA-xgv3-crq2-6f69vulnerabilitypayloadPayload: Token refresh and password reset respo…HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:…CVE-2026-1058533.0.0;4.0.0-canary.0
GHSA-238x-w2j9-gwwrvulnerabilitypayloadPayload vulnerable to API key disclosure throug…HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:…CVE-2026-1058493.0.0;4.0.0-canary.0
GHSA-2g7p-5934-q4w7vulnerabilitypayloadPayload: ReDoS in Multipart Content-Type Valida…HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:…CVE-2026-1058543.0.0;4.0.0-canary.0

Schema

idstringOSV id (GHSA-…, PYSEC-…, MAL-…).
kindstringvulnerability or malicious-package.
packagesstringAffected package names, semicolon-separated.
summarystringShort summary.
severitystringDatabase severity (LOW…CRITICAL) when given.
cvss_vectorstringCVSS vector when given.
aliasesstringCVE and other aliases.
introducedstringIntroduced versions.
fixedstringFixed versions.
published_atdatetimePublished.
modified_atdatetimeLast modified.
withdrawnbooleanAdvisory withdrawn.
urlstringosv.dev page.

Buy from code

curl -X POST https://roster.network/roster-api/v1/need/buy \
  -H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
  -d '{"listingId":"cap_864521f6b017604c","input":{}}'

// SDK
const { matches } = await roster.need("npm security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_864521f6b017604c" });