Roster Data · Feed
PyPI security advisories & malicious packages feed (OSV)
Rolling 30-day feed of new and updated PyPI security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.
What you get
The latest items as JSON. Filter with since, q, or limit. Includes attribution.
Recent items · filter by date or text
- Price
- 0.01 USDC
- Freshness
- Updated 4 h ago
- Refresh
- every 3 hours
- Rows
- 212 · 108 KB
Source & license
- OSV — Open Source Vulnerabilities · CC-BY-4.0
Source: OSV.dev (CC BY 4.0); individual advisories carry their upstream database attribution.
Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.
Sample
| id | kind | packages | summary | severity | cvss_vector | aliases | introduced |
|---|---|---|---|---|---|---|---|
| GHSA-5293-mq8x-g3xj | vulnerability | openapi-python-client | openapi-python-client: Malicious OpenAPI Docume… | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:… | CVE-2026-105801 | 0 |
| GHSA-2r3x-4mrv-mcxf | vulnerability | vyper | Vyper: Memory corruption using function calls w… | MODERATE | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:… | — | 0 |
| GHSA-4v7v-gqf9-ww2g | vulnerability | vyper | Vyper: Call stack corruption when passing compl… | MODERATE | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:… | — | 0 |
| GHSA-vg88-3v92-rjx2 | vulnerability | vyper | Vyper: Return inside for loop more than 1 level… | MODERATE | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:… | — | 0.1.0b10 |
| GHSA-94p9-xgh2-xp45 | vulnerability | virtualenv | virtualenv: Downloaded seed wheels (pip/setupto… | HIGH | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:… | BIT-virtualenv-2026-102930;CVE-2026-102930;PYSE… | 0 |
Schema
| id | string | OSV id (GHSA-…, PYSEC-…, MAL-…). |
| kind | string | vulnerability or malicious-package. |
| packages | string | Affected package names, semicolon-separated. |
| summary | string | Short summary. |
| severity | string | Database severity (LOW…CRITICAL) when given. |
| cvss_vector | string | CVSS vector when given. |
| aliases | string | CVE and other aliases. |
| introduced | string | Introduced versions. |
| fixed | string | Fixed versions. |
| published_at | datetime | Published. |
| modified_at | datetime | Last modified. |
| withdrawn | boolean | Advisory withdrawn. |
| url | string | osv.dev page. |
Buy from code
curl -X POST https://roster.network/roster-api/v1/need/buy \
-H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
-d '{"listingId":"cap_e203537d2ebf804b","input":{}}'
// SDK
const { matches } = await roster.need("PyPI security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_e203537d2ebf804b" });