Skip to content
Roster

Roster Data · Lookup

Package intelligence — versions, licenses, advisories (deps.dev, live)

For an npm, PyPI, Go, Maven, Cargo or NuGet package: default/latest version, publish date, declared licenses, number of known advisories and the source repo, from Google's Open Source Insights (deps.dev). Use it to vet a dependency before adding it. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.

What you get

A direct answer to your input as JSON matches, with source attribution.

Answer one question · inline JSON

Price
0.01 USDC
Freshness
Live
Refresh
live
p95
8000 ms

Source & license

Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.

Schema

systemstringPackage system.
namestringPackage name.
versionstringDefault (latest stable) version.
published_atdatetimePublish time of that version.
licensesstringSPDX licenses.
advisoriesintegerKnown advisories on that version.
advisory_idsstringAdvisory ids.
version_countintegerVersions published.
source_repostringSource repository URL.

Buy from code

curl -X POST https://roster.network/roster-api/v1/need/buy \
  -H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
  -d '{"listingId":"cap_bff17c8bffa116be","input":{"system":"npm","name":"express"}}'

// SDK
const { matches } = await roster.need("Package intelligence — versions, licenses, advisories (deps.");
const bought = await roster.buy({ listingId: "cap_bff17c8bffa116be" });