query_package
CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VERBATIM: events plus one render-safe projection — fixed (the upgrade targets) or affected_through (the last VULNERABLE version, never a fix). This tool does NOT evaluate version membership — compare versions on your side with your ecosystem’s own semantics. Covers CVE-linked, GitHub-reviewed OSS advisories via OSV.dev; absence is not evidence of safety.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Package name, verbatim (e.g. @babel/core, org.jenkins-ci.main:jenkins-core) | |
| purl | No | Package URL, e.g. pkg:npm/lodash or pkg:maven/org.apache.logging.log4j/log4j-core | |
| ecosystem | No | OSV ecosystem (npm, PyPI, Maven, Go, crates.io, Packagist, RubyGems, NuGet, …) or purl type (pypi, cargo, composer, gem, golang, …) |