Skip to content
Roster

Roster Data · Feed

Go security advisories & malicious packages feed (OSV)

Rolling 30-day feed of new and updated Go security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.

What you get

The latest items as JSON. Filter with since, q, or limit. Includes attribution.

Recent items · filter by date or text

Price
0.01 USDC
Freshness
Updated 4 h ago
Refresh
every 3 hours
Rows
154 · 79 KB

Source & license

Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.

Sample

idkindpackagessummaryseveritycvss_vectoraliasesintroduced
GHSA-q7hv-xx6h-q2x8vulnerabilitygithub.com/external-secrets/external-secretsExternal Secrets Operator: label enforcement by…HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NCVE-2026-262870.10.0
GO-2026-6089vulnerabilitystdlibApply ReadHeaderTimeout when doing unencrypted …——BIT-golang-2026-56853;CVE-2026-568530;1.26.0-0;1.27.0-0
GHSA-qqj6-54q6-cxv6vulnerabilitysnowflake-sdk;snowflake-connector-python;github…Snowflake drivers writes sensitive information …MODERATECVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NCVE-2026-865970
GHSA-p5x9-j974-rpfpvulnerabilitygithub.com/grafana/grafanaGrafana legacy correlations allow cross-tenant …LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:NBIT-grafana-2026-21727;CVE-2026-217270
GHSA-4wwp-f6gw-6qm5vulnerabilitygithub.com/siyuan-note/siyuan/kernelSiYuan: TLS Private Keys Readable via getFile (…MODERATE—CVE-2026-851750

Schema

idstringOSV id (GHSA-…, PYSEC-…, MAL-…).
kindstringvulnerability or malicious-package.
packagesstringAffected package names, semicolon-separated.
summarystringShort summary.
severitystringDatabase severity (LOW…CRITICAL) when given.
cvss_vectorstringCVSS vector when given.
aliasesstringCVE and other aliases.
introducedstringIntroduced versions.
fixedstringFixed versions.
published_atdatetimePublished.
modified_atdatetimeLast modified.
withdrawnbooleanAdvisory withdrawn.
urlstringosv.dev page.

Buy from code

curl -X POST https://roster.network/roster-api/v1/need/buy \
  -H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
  -d '{"listingId":"cap_a2609ec636a2c954","input":{}}'

// SDK
const { matches } = await roster.need("Go security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_a2609ec636a2c954" });