Roster Data · Lookup
Package intelligence — versions, licenses, advisories (deps.dev, live)
For an npm, PyPI, Go, Maven, Cargo or NuGet package: default/latest version, publish date, declared licenses, number of known advisories and the source repo, from Google's Open Source Insights (deps.dev). Use it to vet a dependency before adding it. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.
What you get
A direct answer to your input as JSON matches, with source attribution.
Answer one question · inline JSON
- Price
- 0.01 USDC
- Freshness
- Live
- Refresh
- live
- p95
- 8000 ms
Source & license
- Open Source Insights (deps.dev) · CC-BY-4.0
Source: Open Source Insights, deps.dev (CC BY 4.0).
Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.
Schema
| system | string | Package system. |
| name | string | Package name. |
| version | string | Default (latest stable) version. |
| published_at | datetime | Publish time of that version. |
| licenses | string | SPDX licenses. |
| advisories | integer | Known advisories on that version. |
| advisory_ids | string | Advisory ids. |
| version_count | integer | Versions published. |
| source_repo | string | Source repository URL. |
Buy from code
curl -X POST https://roster.network/roster-api/v1/need/buy \
-H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
-d '{"listingId":"cap_bff17c8bffa116be","input":{"system":"npm","name":"express"}}'
// SDK
const { matches } = await roster.need("Package intelligence — versions, licenses, advisories (deps.");
const bought = await roster.buy({ listingId: "cap_bff17c8bffa116be" });