Roster Data · Feed
Go security advisories & malicious packages feed (OSV)
Rolling 30-day feed of new and updated Go security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.
What you get
The latest items as JSON. Filter with since, q, or limit. Includes attribution.
Recent items · filter by date or text
- Price
- 0.01 USDC
- Freshness
- Updated 4 h ago
- Refresh
- every 3 hours
- Rows
- 154 · 79 KB
Source & license
- OSV — Open Source Vulnerabilities · CC-BY-4.0
Source: OSV.dev (CC BY 4.0); individual advisories carry their upstream database attribution.
Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.
Sample
| id | kind | packages | summary | severity | cvss_vector | aliases | introduced |
|---|---|---|---|---|---|---|---|
| GHSA-q7hv-xx6h-q2x8 | vulnerability | github.com/external-secrets/external-secrets | External Secrets Operator: label enforcement by… | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N | CVE-2026-26287 | 0.10.0 |
| GO-2026-6089 | vulnerability | stdlib | Apply ReadHeaderTimeout when doing unencrypted … | — | — | BIT-golang-2026-56853;CVE-2026-56853 | 0;1.26.0-0;1.27.0-0 |
| GHSA-qqj6-54q6-cxv6 | vulnerability | snowflake-sdk;snowflake-connector-python;github… | Snowflake drivers writes sensitive information … | MODERATE | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N | CVE-2026-86597 | 0 |
| GHSA-p5x9-j974-rpfp | vulnerability | github.com/grafana/grafana | Grafana legacy correlations allow cross-tenant … | LOW | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N | BIT-grafana-2026-21727;CVE-2026-21727 | 0 |
| GHSA-4wwp-f6gw-6qm5 | vulnerability | github.com/siyuan-note/siyuan/kernel | SiYuan: TLS Private Keys Readable via getFile (… | MODERATE | — | CVE-2026-85175 | 0 |
Schema
| id | string | OSV id (GHSA-…, PYSEC-…, MAL-…). |
| kind | string | vulnerability or malicious-package. |
| packages | string | Affected package names, semicolon-separated. |
| summary | string | Short summary. |
| severity | string | Database severity (LOW…CRITICAL) when given. |
| cvss_vector | string | CVSS vector when given. |
| aliases | string | CVE and other aliases. |
| introduced | string | Introduced versions. |
| fixed | string | Fixed versions. |
| published_at | datetime | Published. |
| modified_at | datetime | Last modified. |
| withdrawn | boolean | Advisory withdrawn. |
| url | string | osv.dev page. |
Buy from code
curl -X POST https://roster.network/roster-api/v1/need/buy \
-H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
-d '{"listingId":"cap_a2609ec636a2c954","input":{}}'
// SDK
const { matches } = await roster.need("Go security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_a2609ec636a2c954" });