Dependency vulnerability check
vuln_checkKnown security vulnerabilities for a package version (npm, PyPI, crates, Go, Maven, NuGet, RubyGems, Packagist) with severity, CVE/GHSA ids, and the version that fixes each. Queries OSV.dev, the open vulnerability database that aggregates GitHub advisories, PyPA, RustSec, Go and more. Pass up to 50 packages at once as "ecosystem:name@version" to audit a lockfile. Price: $0.002 per call (10 free/day).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | ||
| version | No | ||
| packages | No | e.g. ["npm:lodash@4.17.15","pypi:requests@2.19.0"] | |
| ecosystem | No | npm |