Skip to content
Roster

Roster Data · Feed

PyPI security advisories & malicious packages feed (OSV)

Rolling 30-day feed of new and updated PyPI security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.

What you get

The latest items as JSON. Filter with since, q, or limit. Includes attribution.

Recent items · filter by date or text

Price
0.01 USDC
Freshness
Updated 4 h ago
Refresh
every 3 hours
Rows
212 · 108 KB

Source & license

Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.

Sample

idkindpackagessummaryseveritycvss_vectoraliasesintroduced
GHSA-5293-mq8x-g3xjvulnerabilityopenapi-python-clientopenapi-python-client: Malicious OpenAPI Docume…HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:…CVE-2026-1058010
GHSA-2r3x-4mrv-mcxfvulnerabilityvyperVyper: Memory corruption using function calls w…MODERATECVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:…—0
GHSA-4v7v-gqf9-ww2gvulnerabilityvyperVyper: Call stack corruption when passing compl…MODERATECVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:…—0
GHSA-vg88-3v92-rjx2vulnerabilityvyperVyper: Return inside for loop more than 1 level…MODERATECVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:…—0.1.0b10
GHSA-94p9-xgh2-xp45vulnerabilityvirtualenvvirtualenv: Downloaded seed wheels (pip/setupto…HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:…BIT-virtualenv-2026-102930;CVE-2026-102930;PYSE…0

Schema

idstringOSV id (GHSA-…, PYSEC-…, MAL-…).
kindstringvulnerability or malicious-package.
packagesstringAffected package names, semicolon-separated.
summarystringShort summary.
severitystringDatabase severity (LOW…CRITICAL) when given.
cvss_vectorstringCVSS vector when given.
aliasesstringCVE and other aliases.
introducedstringIntroduced versions.
fixedstringFixed versions.
published_atdatetimePublished.
modified_atdatetimeLast modified.
withdrawnbooleanAdvisory withdrawn.
urlstringosv.dev page.

Buy from code

curl -X POST https://roster.network/roster-api/v1/need/buy \
  -H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
  -d '{"listingId":"cap_e203537d2ebf804b","input":{}}'

// SDK
const { matches } = await roster.need("PyPI security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_e203537d2ebf804b" });