Skip to main content
Glama

Server Details

Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.

If you are the author of this connector, you can claim ownership by verifying the domain or GitHub account it belongs to. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Uptime
100.0% over 48 days
Last Tested
Transport
Streamable HTTP · MCP 2025-11-25
URL
Repository
cyanheads/osv-advisory-mcp-server
GitHub Stars
2
Server Listing
osv-advisory-mcp-server

TDQS

A4.6/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: single-package query, batch query, full advisory lookup, and ecosystem discovery. The batch and single query tools are closely related but their scopes are explicit and non-overlapping.

Naming Consistency5/5

All tool names follow the same osv_ prefix plus a verb_noun pattern: get_vulnerability, list_ecosystems, query_batch, query_package. Naming conventions are uniform and predictable throughout.

Tool Count5/5

Four tools form a focused, well-scoped set for the OSV advisory domain. Each tool covers a distinct operation and none feel redundant or extraneous.

Completeness5/5

The set covers the core OSV API surface: querying by package, batch querying, fetching full advisory details, and listing valid ecosystems. No obvious dead ends exist for the server's stated purpose.

Available Tools

4 tools
osv_get_vulnerabilityOsv Get VulnerabilityA
Read-onlyIdempotent
Inspect

Fetch the full advisory record for an OSV vulnerability ID. Returns the complete record: summary, full details text, CVE aliases, all affected packages and version ranges, fix versions, CVSS severity vectors, CWE weakness IDs, and references. Use when osv_query_package or osv_query_batch returns a vuln ID and you need the full advisory context — eligibility criteria, scope of affected packages, or remediation guidance.

ParametersJSON Schema
NameRequiredDescriptionDefault
idYesOne exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include "GHSA-" (GitHub), "PYSEC-" (PyPI), "RUSTSEC-" (Rust), "GO-" (Go), "DSA-"/"DLA-" (Debian), "USN-" (Ubuntu), "RHSA-" (Red Hat), and "CVE-". No wildcards or partial IDs — take IDs from osv_query_package or osv_query_batch results. Example: "GHSA-29mw-wpgm-hmr9".

Output Schema

ParametersJSON Schema
NameRequiredDescription
idNoOSV vulnerability ID.
errorNoPresent when the call failed. Absent on success.
cweIdsNoCWE weakness classifications (e.g. ["CWE-79"]). Present on GitHub Advisory Database records; empty otherwise.
aliasesNoAlternative IDs — usually CVE IDs. Accepted by nvd_get_cve on nist-nvd-mcp-server for CVSS base score, EPSS exploitation probability, and CISA KEV status.
detailsNoFull advisory text, typically in Markdown. May include proof-of-concept, reproduction steps, or remediation guidance.
summaryNoOne-line advisory description.
affectedNoAll affected packages and their version ranges. An advisory may span multiple packages or ecosystems.
modifiedNoISO 8601 timestamp of last modification.
severityNoRecord-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately.
publishedNoISO 8601 timestamp when published.
withdrawnNoISO 8601 timestamp when this advisory was withdrawn. Present ONLY on withdrawn advisories — a withdrawn record has been retracted and must not be treated as an active vulnerability.
referencesNoAdvisory references — NVD links, patches, vendor advisories, PoC reports.
schemaVersionNoOSV schema version this record conforms to (e.g. "1.7.3").
severityLabelNoSeverity label ("LOW", "MODERATE", "HIGH", "CRITICAL") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label.
severitySourceNoThe severity entry severityLabel was derived from. Null exactly when the label is.

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint and idempotentHint, and the description adds substantial behavioral detail beyond that: it lists the full advisory fields returned (summary, details, aliases, affected packages, fix versions, CVSS, CWE, references). It also notes the ID must be exact and taken from query results, which is useful operational context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, front-loaded with the action and output, and the usage guidance is clear and efficient. No filler or redundant phrasing; every clause adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, the description does not need to specify return structure further, but it does, which is a bonus. It covers when to use, what to expect, and the source of the input ID. There are no missing critical elements for safe and correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%: the id parameter already has a thorough description covering pattern, prefix examples, case-sensitivity, and no-wildcard requirement. The tool description adds no parameter-level meaning beyond restating that the ID is an OSV vulnerability ID, so it neither improves nor detracts from the schema baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Fetch the full advisory record for an OSV vulnerability ID.' It then enumerates the complete returned payload and explicitly names the sibling query tools as the source of IDs, clearly distinguishing this retrieval tool from the query tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit when-to-use instructions: 'Use when osv_query_package or osv_query_batch returns a vuln ID and you need the full advisory context.' This names the alternatives and the precise condition that selects this tool, leaving no ambiguity.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

osv_list_ecosystemsOsv List EcosystemsA
Read-onlyIdempotent
Inspect

Return the supported ecosystem identifier strings for osv_query_package and osv_query_batch: every ecosystem the OSV schema names that OSV.dev accepts at query time, plus GIT, as verified on 2026-09-24. Ecosystem strings are case-sensitive exact matches — passing "pypi" instead of "PyPI" returns an error from the API. Use this tool to discover valid ecosystem strings before querying, or to verify an ecosystem identifier from a lockfile format. The list is static and may lag ecosystems added after that date.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
noteNoAdvisory note about list currency and canonical source.
errorNoPresent when the call failed. Absent on success.
ecosystemsNoSupported ecosystem identifier strings. These are case-sensitive exact matches required by the ecosystem parameter of osv_query_package and osv_query_batch.

TDQS

A4.7/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already provide readOnlyHint=true and idempotentHint=true, so the description doesn't need to repeat that. The description adds valuable context: ecosystem strings are case-sensitive, and the list is static and may lag behind new ecosystems as of the verified date. This helps set expectations about the tool's currentness and potential error behavior, which is beyond what annotations convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise but packed with useful information. It front-loads the purpose and then adds critical usage and caveat details in a logical sequence. Each sentence earns its place: purpose, case-sensitivity warning, usage guidance, and freshness caveat. No fluff or repetition.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is an output schema, so the description needn't detail the return format. The description covers everything an agent needs to use this tool correctly: what it returns, why it's useful, the case-sensitivity constraint, and the staleness caveat. Given the zero-parameter nature and strong annotations, this is complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters, and schema coverage is 100% (no properties). The description still adds meaning by explaining the output (a list of ecosystem identifier strings) and its significance, which is useful even without parameters. Since there are no parameters to describe, the baseline of 4 is appropriate as it provides context about the output and its use.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: to return supported ecosystem identifier strings for querying OSV. It specifies the exact resource (ecosystem identifiers) and the action (list), and mentions its role in supporting two sibling tools. It distinguishes itself from siblings by focusing on discovery of valid identifiers rather than querying vulnerabilities.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly tells when to use this tool: before querying (osv_query_package or osv_query_batch) to discover valid ecosystem strings, or to verify an identifier from a lockfile. It also mentions that passing incorrect case (e.g., 'pypi' vs 'PyPI') will cause an error, effectively guiding the agent to use this tool to avoid that. It implicitly differentiates from siblings by positioning this as a discovery/verification step.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

osv_query_batchOsv Query BatchA
Read-onlyIdempotent
Inspect

Query vulnerabilities for multiple packages in one call — the primary tool for dependency audits, SBOM scanning, and lockfile triage. Pass an array of {name, ecosystem, version} tuples (up to 1000). Each entry in the response corresponds positionally to the input. Each finding includes CVE aliases for chaining to nist-nvd-mcp-server for CVSS scoring.

ParametersJSON Schema
NameRequiredDescriptionDefault
packagesYesPackages to audit. One entry per dependency. Positional: result[i] corresponds to packages[i].

Output Schema

ParametersJSON Schema
NameRequiredDescription
errorNoPresent when the call failed. Absent on success.
noticeNoPresent on all-clean or all-errors batches — the aggregate outcome for content-only clients.
resultsNoPer-package results, positionally matching the input array.
summaryNoAggregate statistics across the full batch.
effectiveQueryNoCompact scan summary (package and outcome counts), echoed on edge-case batches for content-only clients.

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The annotations already declare readOnlyHint and idempotentHint, so the description does not need to restate safety. It adds useful behavioral context: responses are positional, the batch supports up to 1000 packages, and findings include CVE aliases for chaining to nist-nvd-mcp-server. This goes beyond the structured annotations without contradicting them.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tightly packed sentences: the first establishes the tool's primary role, the second specifies input shape and limits, and the third explains output correspondence and chaining. Every sentence earns its place with no redundant elaboration.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the presence of an output schema, full parameter coverage in the input schema, and annotations covering safety and idempotency, the description provides everything needed to select and invoke the tool correctly. It also adds cross-server chaining guidance, which is valuable contextual information.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with the packages array and its nested fields already well documented. The description reinforces the tuple shape and positional semantics, but most of this information is already present in the schema, so the added value is limited to emphasis rather than new detail.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Query vulnerabilities') with a clear resource ('multiple packages in one call') and immediately identifies its main use cases: dependency audits, SBOM scanning, and lockfile triage. This makes it easy to distinguish from the sibling tools, especially osv_query_package, since batch behavior is called out up front.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly frames the tool as 'the primary tool for dependency audits, SBOM scanning, and lockfile triage', giving clear context on when to reach for it. It does not explicitly name alternatives or state when not to use it, but the 'primary tool' wording combined with the batch focus provides adequate usage direction.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

osv_query_packageOsv Query PackageA
Read-onlyIdempotent
Inspect

Query known vulnerabilities for a single package version across any supported ecosystem. Returns all matching OSV advisories with severity (CVSS vectors), CVE aliases, affected version ranges, and the fixed versions listed for the queried package. Use osv_list_ecosystems to validate the ecosystem string before querying — ecosystem strings are case-sensitive exact matches and an invalid value returns an error, not empty results.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesPackage name as it appears in the ecosystem (e.g. "express", "requests", "serde"). Case-sensitive.
versionYesPackage version to check (e.g. "4.17.1", "3.1.4", "1.0.0"). Must be an exact version string, not a range.
ecosystemYesEcosystem identifier. Must be an exact match (case-sensitive). Use osv_list_ecosystems to see valid values. Examples: "npm", "PyPI", "crates.io", "Go", "Maven", "NuGet".

Output Schema

ParametersJSON Schema
NameRequiredDescription
errorNoPresent when the call failed. Absent on success.
vulnsNoVulnerabilities matching this package version. An empty array means no known vulnerabilities ONLY when truncated is false.
noticeNoPresent on the clean path — confirms no known vulnerabilities for the queried package.
queryMetaNoQuery parameters as submitted.
truncatedNoTrue when OSV returned more result pages than the fetch cap could follow — the vulnerability list may be INCOMPLETE. A truncated empty list is NOT a clean result; raise OSV_QUERY_MAX_PAGES or narrow the query.
effectiveQueryNoThe package@version (ecosystem) tuple as queried, echoed for content-only clients.

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, openWorldHint, and idempotentHint, so the safety profile is covered. The description adds useful behavioral detail: ecosystem matching is case-sensitive exact, invalid values produce an error, and returned advisories include severity, aliases, affected ranges, and fixed versions. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, front-loaded with the core action, followed by return contents and a usage prerequisite. Every sentence contributes necessary information with no filler or repetition of schema details.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The output schema already handles return structure, so the description only needs to cover invocation scope, the ecosystem validation prerequisite, and the failure mode. All of that is present, making the definition complete for correct single-package query usage.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with each parameter already documented with examples and case-sensitivity notes. The description reinforces the exact-version requirement and adds the invalid-ecosystem error behavior, but it does not meaningfully expand on what the schema already provides, so the baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Query known vulnerabilities for a single package version.' It also lists concrete return contents (severity, CVEs, affected ranges, fixed versions) and the 'single package version' scope distinguishes it from the sibling osv_query_batch.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly tells the agent to use osv_list_ecosystems to validate the ecosystem string before querying, and warns that invalid values error rather than return empty. It does not explicitly state when to prefer osv_get_vulnerability or osv_query_batch, so exclusions are absent, but the intended usage context is clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 3 tool updates
    • Changedosv_get_vulnerability12 fields changed
      • changedInput schema / properties / id / description
        Previous value: -"OSV vulnerability ID. Accepts any prefix: \"GHSA-\" (GitHub), \"PYSEC-\" (Python), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"CVE-\" (fallback direct lookups). Example: \"GHSA-29mw-wpgm-hmr9\"."New value: +"One exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include \"GHSA-\" (GitHub), \"PYSEC-\" (PyPI), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"USN-\" (Ubuntu), \"RHSA-\" (Red Hat), and \"CVE-\". No wildcards or partial IDs — take IDs from osv_query_package or osv_query_batch results. Example: \"GHSA-29mw-wpgm-hmr9\"."
      • removedInput schema / properties / id / minLength
        Removed value: -1
      • changedInput schema / properties / id / pattern
        Previous value: -"\\S"New value: +"^[A-Za-z][A-Za-z0-9_]*-\\S(.*\\S)?$"
      • changedOutput schema / anyOf
        Previous value: -[
        -  {
        -    "not": {
        -      "required": [
        -        "error"
        -      ]
        -    },
        -    "required": [
        -      "id",
        -      "summary",
        -      "details",
        -      "aliases",
        -      "published",
        -      "modified",
        -      "severity",
        -      "severityLabel",
        -      "affected",
        -      "cweIds",
        -      "references",
        -      "schemaVersion"
        -    ]
        -  },
        -  {
        -    "required": [
        -      "error"
        -    ]
        -  }
        -]New value: +[
        +  {
        +    "not": {
        +      "required": [
        +        "error"
        +      ]
        +    },
        +    "required": [
        +      "id",
        +      "summary",
        +      "details",
        +      "aliases",
        +      "published",
        +      "modified",
        +      "severity",
        +      "severityLabel",
        +      "severitySource",
        +      "affected",
        +      "cweIds",
        +      "references",
        +      "schemaVersion"
        +    ]
        +  },
        +  {
        +    "required": [
        +      "error"
        +    ]
        +  }
        +]
      • changedOutput schema / properties / affected / items / properties / ranges / items / properties / fixed / description
        Previous value: -"First safe version (convenience view — the last \"fixed\" event; see events[])."New value: +"The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[])."
      • addedOutput schema / properties / affected / items / properties / severity
        Added value: +{
        +  "description": "Severity entries scoped to this package. Present only when the advisory scores packages separately; the record-level severity is then empty.",
        +  "items": {
        +    "additionalProperties": false,
        +    "description": "One package-level severity entry.",
        +    "properties": {
        +      "score": {
        +        "description": "CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\".",
        +        "type": "string"
        +      },
        +      "type": {
        +        "description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\".",
        +        "type": "string"
        +      }
        +    },
        +    "required": [
        +      "type",
        +      "score"
        +    ],
        +    "type": "object"
        +  },
        +  "type": "array"
        +}
      • changedOutput schema / properties / severity / description
        Previous value: -"CVSS severity entries. Empty for unscored advisories."New value: +"Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately."
      • changedOutput schema / properties / severity / items / description
        Previous value: -"One CVSS severity entry."New value: +"One record-level severity entry."
      • changedOutput schema / properties / severity / items / properties / score / description
        Previous value: -"CVSS vector string."New value: +"CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
      • changedOutput schema / properties / severity / items / properties / type / description
        Previous value: -"CVSS version: \"CVSS_V3\", \"CVSS_V4\", or \"CVSS_V2\"."New value: +"Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
      • changedOutput schema / properties / severityLabel / description
        Previous value: -"Human-readable severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\"). Present on GHSA-sourced records; null when not available."New value: +"Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label."
      • addedOutput schema / properties / severitySource
        Added value: +{
        +  "anyOf": [
        +    {
        +      "additionalProperties": false,
        +      "properties": {
        +        "computedScore": {
        +          "description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
        +          "type": "number"
        +        },
        +        "score": {
        +          "description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.",
        +          "type": "string"
        +        },
        +        "type": {
        +          "description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.",
        +          "enum": [
        +            "database_specific",
        +            "Ubuntu",
        +            "CVSS_V3",
        +            "CVSS_V4"
        +          ],
        +          "type": "string"
        +        }
        +      },
        +      "required": [
        +        "type",
        +        "score"
        +      ],
        +      "type": "object"
        +    },
        +    {
        +      "type": "null"
        +    }
        +  ],
        +  "description": "The severity entry severityLabel was derived from. Null exactly when the label is."
        +}
    • Changedosv_query_batch6 fields changed
      • removedInput schema / properties / packages / items / properties / ecosystem / minLength
        Removed value: -1
      • removedInput schema / properties / packages / items / properties / name / minLength
        Removed value: -1
      • removedInput schema / properties / packages / items / properties / version / minLength
        Removed value: -1
      • changedOutput schema / properties / results / items / properties / vulns / items / properties / fixedVersions / description
        Previous value: -"First safe version(s) to upgrade to. Empty if no fix exists."New value: +"Every fixed version the advisory lists for this row's package, in record order — one per affected interval, typically one per release line. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."
      • changedOutput schema / properties / results / items / properties / vulns / items / properties / fixedVersions / items / description
        Previous value: -"A first-safe version string."New value: +"A version that fixes the vulnerability for this package."
      • changedOutput schema / properties / results / items / properties / vulns / items / properties / severityLabel / description
        Previous value: -"Severity label: \"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\", or null."New value: +"Severity label: \"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\", or null. Same derivation as osv_query_package: database_specific.severity, then an Ubuntu priority, then the highest CVSS v3/v4 score, using this row's package-level severity entries when the record has none."
    • Changedosv_query_package13 fields changed
      • removedInput schema / properties / ecosystem / minLength
        Removed value: -1
      • removedInput schema / properties / name / minLength
        Removed value: -1
      • removedInput schema / properties / version / minLength
        Removed value: -1
      • changedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / fixed / description
        Previous value: -"First safe version — the version to upgrade to (convenience view — see events[])."New value: +"The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[])."
      • changedOutput schema / properties / vulns / items / properties / fixedVersions / description
        Previous value: -"First safe version(s) per affected package entry. Empty if no fix exists yet."New value: +"Every fixed version the advisory lists for the queried package, in record order. A multi-interval range contributes one per interval (typically one per release line); affectedRanges shows which interval each one closes. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."
      • changedOutput schema / properties / vulns / items / properties / fixedVersions / items / description
        Previous value: -"A first-safe version string."New value: +"A version that fixes the vulnerability for the queried package."
      • changedOutput schema / properties / vulns / items / properties / severity / description
        Previous value: -"CVSS severity entries. May be empty for advisories not yet scored."New value: +"Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for advisories not yet scored and for advisories that score each affected package separately — severitySource then carries the queried package entry used."
      • changedOutput schema / properties / vulns / items / properties / severity / items / description
        Previous value: -"One CVSS severity entry."New value: +"One record-level severity entry."
      • changedOutput schema / properties / vulns / items / properties / severity / items / properties / score / description
        Previous value: -"CVSS vector string (e.g. \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\")."New value: +"CVSS vector string (e.g. \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\"), or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
      • changedOutput schema / properties / vulns / items / properties / severity / items / properties / type / description
        Previous value: -"CVSS version: \"CVSS_V3\", \"CVSS_V4\", or \"CVSS_V2\"."New value: +"Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
      • changedOutput schema / properties / vulns / items / properties / severityLabel / description
        Previous value: -"Human-readable severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\"). Present on GHSA-sourced records; null otherwise."New value: +"Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses the queried package's affected-level severity entries when the record-level list is empty. Null when no source yields a label."
      • addedOutput schema / properties / vulns / items / properties / severitySource
        Added value: +{
        +  "anyOf": [
        +    {
        +      "additionalProperties": false,
        +      "properties": {
        +        "computedScore": {
        +          "description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
        +          "type": "number"
        +        },
        +        "score": {
        +          "description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.",
        +          "type": "string"
        +        },
        +        "type": {
        +          "description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.",
        +          "enum": [
        +            "database_specific",
        +            "Ubuntu",
        +            "CVSS_V3",
        +            "CVSS_V4"
        +          ],
        +          "type": "string"
        +        }
        +      },
        +      "required": [
        +        "type",
        +        "score"
        +      ],
        +      "type": "object"
        +    },
        +    {
        +      "type": "null"
        +    }
        +  ],
        +  "description": "The severity entry severityLabel was derived from. Null exactly when the label is."
        +}
      • changedOutput schema / properties / vulns / items / required
        Previous value: -[
        -  "id",
        -  "summary",
        -  "aliases",
        -  "severity",
        -  "severityLabel",
        -  "fixedVersions",
        -  "affectedRanges",
        -  "cweIds",
        -  "published",
        -  "modified"
        -]New value: +[
        +  "id",
        +  "summary",
        +  "aliases",
        +  "severity",
        +  "severityLabel",
        +  "severitySource",
        +  "fixedVersions",
        +  "affectedRanges",
        +  "cweIds",
        +  "published",
        +  "modified"
        +]
  2. 3 tool updates
    • Changedosv_get_vulnerability2 fields changed
      • removedOutput schema / properties / severityLabel / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / severityLabel / type
        Added value: +[
        +  "string",
        +  "null"
        +]
    • Changedosv_query_batch6 fields changed
      • removedOutput schema / properties / results / items / properties / error / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / results / items / properties / error / type
        Added value: +[
        +  "string",
        +  "null"
        +]
      • removedOutput schema / properties / results / items / properties / vulns / items / properties / severityLabel / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / results / items / properties / vulns / items / properties / severityLabel / type
        Added value: +[
        +  "string",
        +  "null"
        +]
      • removedOutput schema / properties / summary / properties / worstSeverity / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / summary / properties / worstSeverity / type
        Added value: +[
        +  "string",
        +  "null"
        +]
    • Changedosv_query_package2 fields changed
      • removedOutput schema / properties / vulns / items / properties / severityLabel / anyOf
        Removed value: -[
        -  {
        -    "type": "string"
        -  },
        -  {
        -    "type": "null"
        -  }
        -]
      • addedOutput schema / properties / vulns / items / properties / severityLabel / type
        Added value: +[
        +  "string",
        +  "null"
        +]
  3. 4 tool updates
    • Changedosv_get_vulnerability6 fields changed
      • changedInput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedInput schema / additionalProperties
        Added value: +false
      • changedOutput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedOutput schema / anyOf
        Added value: +[
        +  {
        +    "not": {
        +      "required": [
        +        "error"
        +      ]
        +    },
        +    "required": [
        +      "id",
        +      "summary",
        +      "details",
        +      "aliases",
        +      "published",
        +      "modified",
        +      "severity",
        +      "severityLabel",
        +      "affected",
        +      "cweIds",
        +      "references",
        +      "schemaVersion"
        +    ]
        +  },
        +  {
        +    "required": [
        +      "error"
        +    ]
        +  }
        +]
      • addedOutput schema / properties / error
        Added value: +{
        +  "additionalProperties": {},
        +  "description": "Present when the call failed. Absent on success.",
        +  "properties": {
        +    "code": {
        +      "description": "JSON-RPC error code for this failure.",
        +      "maximum": 9007199254740991,
        +      "minimum": -9007199254740991,
        +      "type": "integer"
        +    },
        +    "data": {
        +      "additionalProperties": {},
        +      "properties": {
        +        "reason": {
        +          "description": "Machine-readable failure mode. Declared by this tool: `vulnerability_not_found`: The requested OSV ID does not exist in the database. Other values are possible when a failure originates below the handler.",
        +          "examples": [
        +            "vulnerability_not_found"
        +          ],
        +          "type": "string"
        +        },
        +        "recovery": {
        +          "additionalProperties": {},
        +          "description": "Actionable next step for the caller.",
        +          "properties": {
        +            "hint": {
        +              "type": "string"
        +            }
        +          },
        +          "required": [
        +            "hint"
        +          ],
        +          "type": "object"
        +        },
        +        "retryable": {
        +          "description": "Whether retrying may succeed.",
        +          "type": "boolean"
        +        }
        +      },
        +      "type": "object"
        +    },
        +    "message": {
        +      "description": "Human-readable description of what went wrong.",
        +      "type": "string"
        +    }
        +  },
        +  "required": [
        +    "code",
        +    "message"
        +  ],
        +  "type": "object"
        +}
      • removedOutput schema / required
        Removed value: -[
        -  "id",
        -  "summary",
        -  "details",
        -  "aliases",
        -  "published",
        -  "modified",
        -  "severity",
        -  "severityLabel",
        -  "affected",
        -  "cweIds",
        -  "references",
        -  "schemaVersion"
        -]
    • Changedosv_list_ecosystems6 fields changed
      • changedInput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedInput schema / additionalProperties
        Added value: +false
      • changedOutput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedOutput schema / anyOf
        Added value: +[
        +  {
        +    "not": {
        +      "required": [
        +        "error"
        +      ]
        +    },
        +    "required": [
        +      "ecosystems",
        +      "note"
        +    ]
        +  },
        +  {
        +    "required": [
        +      "error"
        +    ]
        +  }
        +]
      • addedOutput schema / properties / error
        Added value: +{
        +  "additionalProperties": {},
        +  "description": "Present when the call failed. Absent on success.",
        +  "properties": {
        +    "code": {
        +      "description": "JSON-RPC error code for this failure.",
        +      "maximum": 9007199254740991,
        +      "minimum": -9007199254740991,
        +      "type": "integer"
        +    },
        +    "data": {
        +      "additionalProperties": {},
        +      "properties": {
        +        "reason": {
        +          "description": "Machine-readable failure mode.",
        +          "type": "string"
        +        },
        +        "recovery": {
        +          "additionalProperties": {},
        +          "description": "Actionable next step for the caller.",
        +          "properties": {
        +            "hint": {
        +              "type": "string"
        +            }
        +          },
        +          "required": [
        +            "hint"
        +          ],
        +          "type": "object"
        +        },
        +        "retryable": {
        +          "description": "Whether retrying may succeed.",
        +          "type": "boolean"
        +        }
        +      },
        +      "type": "object"
        +    },
        +    "message": {
        +      "description": "Human-readable description of what went wrong.",
        +      "type": "string"
        +    }
        +  },
        +  "required": [
        +    "code",
        +    "message"
        +  ],
        +  "type": "object"
        +}
      • removedOutput schema / required
        Removed value: -[
        -  "ecosystems",
        -  "note"
        -]
    • Changedosv_query_batch6 fields changed
      • changedInput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedInput schema / additionalProperties
        Added value: +false
      • changedOutput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedOutput schema / anyOf
        Added value: +[
        +  {
        +    "not": {
        +      "required": [
        +        "error"
        +      ]
        +    },
        +    "required": [
        +      "results",
        +      "summary"
        +    ]
        +  },
        +  {
        +    "required": [
        +      "error"
        +    ]
        +  }
        +]
      • addedOutput schema / properties / error
        Added value: +{
        +  "additionalProperties": {},
        +  "description": "Present when the call failed. Absent on success.",
        +  "properties": {
        +    "code": {
        +      "description": "JSON-RPC error code for this failure.",
        +      "maximum": 9007199254740991,
        +      "minimum": -9007199254740991,
        +      "type": "integer"
        +    },
        +    "data": {
        +      "additionalProperties": {},
        +      "properties": {
        +        "reason": {
        +          "description": "Machine-readable failure mode.",
        +          "type": "string"
        +        },
        +        "recovery": {
        +          "additionalProperties": {},
        +          "description": "Actionable next step for the caller.",
        +          "properties": {
        +            "hint": {
        +              "type": "string"
        +            }
        +          },
        +          "required": [
        +            "hint"
        +          ],
        +          "type": "object"
        +        },
        +        "retryable": {
        +          "description": "Whether retrying may succeed.",
        +          "type": "boolean"
        +        }
        +      },
        +      "type": "object"
        +    },
        +    "message": {
        +      "description": "Human-readable description of what went wrong.",
        +      "type": "string"
        +    }
        +  },
        +  "required": [
        +    "code",
        +    "message"
        +  ],
        +  "type": "object"
        +}
      • removedOutput schema / required
        Removed value: -[
        -  "results",
        -  "summary"
        -]
    • Changedosv_query_package6 fields changed
      • changedInput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedInput schema / additionalProperties
        Added value: +false
      • changedOutput schema / $schema
        Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
      • addedOutput schema / anyOf
        Added value: +[
        +  {
        +    "not": {
        +      "required": [
        +        "error"
        +      ]
        +    },
        +    "required": [
        +      "vulns",
        +      "truncated",
        +      "queryMeta"
        +    ]
        +  },
        +  {
        +    "required": [
        +      "error"
        +    ]
        +  }
        +]
      • addedOutput schema / properties / error
        Added value: +{
        +  "additionalProperties": {},
        +  "description": "Present when the call failed. Absent on success.",
        +  "properties": {
        +    "code": {
        +      "description": "JSON-RPC error code for this failure.",
        +      "maximum": 9007199254740991,
        +      "minimum": -9007199254740991,
        +      "type": "integer"
        +    },
        +    "data": {
        +      "additionalProperties": {},
        +      "properties": {
        +        "reason": {
        +          "description": "Machine-readable failure mode. Declared by this tool: `invalid_ecosystem`: The ecosystem string is not recognized by OSV. Ecosystem names are case-sensitive exact matches. Other values are possible when a failure originates below the handler.",
        +          "examples": [
        +            "invalid_ecosystem"
        +          ],
        +          "type": "string"
        +        },
        +        "recovery": {
        +          "additionalProperties": {},
        +          "description": "Actionable next step for the caller.",
        +          "properties": {
        +            "hint": {
        +              "type": "string"
        +            }
        +          },
        +          "required": [
        +            "hint"
        +          ],
        +          "type": "object"
        +        },
        +        "retryable": {
        +          "description": "Whether retrying may succeed.",
        +          "type": "boolean"
        +        }
        +      },
        +      "type": "object"
        +    },
        +    "message": {
        +      "description": "Human-readable description of what went wrong.",
        +      "type": "string"
        +    }
        +  },
        +  "required": [
        +    "code",
        +    "message"
        +  ],
        +  "type": "object"
        +}
      • removedOutput schema / required
        Removed value: -[
        -  "vulns",
        -  "truncated",
        -  "queryMeta"
        -]
  4. 3 tool updates
    • Changedosv_get_vulnerability2 fields changed
      • addedInput schema / properties / id / minLength
        Added value: +1
      • addedInput schema / properties / id / pattern
        Added value: +"\\S"
    • Changedosv_query_batch6 fields changed
      • addedInput schema / properties / packages / items / properties / ecosystem / minLength
        Added value: +1
      • addedInput schema / properties / packages / items / properties / ecosystem / pattern
        Added value: +"\\S"
      • addedInput schema / properties / packages / items / properties / name / minLength
        Added value: +1
      • addedInput schema / properties / packages / items / properties / name / pattern
        Added value: +"\\S"
      • addedInput schema / properties / packages / items / properties / version / minLength
        Added value: +1
      • addedInput schema / properties / packages / items / properties / version / pattern
        Added value: +"\\S"
    • Changedosv_query_package6 fields changed
      • addedInput schema / properties / ecosystem / minLength
        Added value: +1
      • addedInput schema / properties / ecosystem / pattern
        Added value: +"\\S"
      • addedInput schema / properties / name / minLength
        Added value: +1
      • addedInput schema / properties / name / pattern
        Added value: +"\\S"
      • addedInput schema / properties / version / minLength
        Added value: +1
      • addedInput schema / properties / version / pattern
        Added value: +"\\S"
  5. 3 tool updates
    • Changedosv_get_vulnerability9 fields changed
      • changedOutput schema / properties / affected / items / properties / ecosystem / description
        Previous value: -"Affected package ecosystem."New value: +"Affected package ecosystem. Empty for source-only advisories."
      • changedOutput schema / properties / affected / items / properties / packageName / description
        Previous value: -"Affected package name."New value: +"Affected package name. Empty for source-only advisories (GIT ranges with no package identity)."
      • addedOutput schema / properties / affected / items / properties / ranges / items / properties / events
        Added value: +{
        +  "description": "Ordered event boundaries defining the affected interval(s) — the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.",
        +  "items": {
        +    "additionalProperties": false,
        +    "description": "One ordered range event.",
        +    "properties": {
        +      "type": {
        +        "description": "Event boundary type: \"introduced\", \"fixed\", \"last_affected\", or \"limit\".",
        +        "type": "string"
        +      },
        +      "value": {
        +        "description": "Version string or commit identifier at this boundary.",
        +        "type": "string"
        +      }
        +    },
        +    "required": [
        +      "type",
        +      "value"
        +    ],
        +    "type": "object"
        +  },
        +  "type": "array"
        +}
      • changedOutput schema / properties / affected / items / properties / ranges / items / properties / fixed / description
        Previous value: -"First safe version."New value: +"First safe version (convenience view — the last \"fixed\" event; see events[])."
      • changedOutput schema / properties / affected / items / properties / ranges / items / properties / introduced / description
        Previous value: -"First affected version."New value: +"First affected version (convenience view — the last \"introduced\" event; see events[] for full interval order)."
      • changedOutput schema / properties / affected / items / properties / ranges / items / properties / lastAffected / description
        Previous value: -"Last affected version when no fix exists."New value: +"Last affected version when no fix exists (convenience view — see events[])."
      • addedOutput schema / properties / affected / items / properties / ranges / items / properties / repo
        Added value: +{
        +  "description": "Source repository URL for GIT ranges. Absent on version ranges.",
        +  "type": "string"
        +}
      • addedOutput schema / properties / affected / items / properties / versions
        Added value: +{
        +  "description": "Explicit affected versions enumerated by the advisory. Absent or empty when affected versions are expressed only as ranges.",
        +  "items": {
        +    "description": "An explicitly-listed affected version.",
        +    "type": "string"
        +  },
        +  "type": "array"
        +}
      • addedOutput schema / properties / withdrawn
        Added value: +{
        +  "description": "ISO 8601 timestamp when this advisory was withdrawn. Present ONLY on withdrawn advisories — a withdrawn record has been retracted and must not be treated as an active vulnerability.",
        +  "type": "string"
        +}
    • Changedosv_query_batch5 fields changed
      • addedOutput schema / properties / results / items / properties / truncated
        Added value: +{
        +  "description": "True when OSV paginated beyond the fetch cap for this package — its result may be INCOMPLETE. A truncated row with no vulnerabilities is NOT confirmed clean.",
        +  "type": "boolean"
        +}
      • changedOutput schema / properties / results / items / required
        Previous value: -[
        -  "name",
        -  "ecosystem",
        -  "version",
        -  "vulnerable",
        -  "error",
        -  "vulnCount",
        -  "vulns"
        -]New value: +[
        +  "name",
        +  "ecosystem",
        +  "version",
        +  "vulnerable",
        +  "truncated",
        +  "error",
        +  "vulnCount",
        +  "vulns"
        +]
      • changedOutput schema / properties / summary / properties / cleanCount / description
        Previous value: -"Packages with no vulnerabilities."New value: +"Packages confirmed clean — no vulnerabilities, no error, and not truncated."
      • addedOutput schema / properties / summary / properties / truncatedCount
        Added value: +{
        +  "description": "Packages whose OSV results were truncated (may be incomplete). A truncated package with no findings is NOT counted as clean.",
        +  "type": "number"
        +}
      • changedOutput schema / properties / summary / required
        Previous value: -[
        -  "totalPackages",
        -  "vulnerableCount",
        -  "cleanCount",
        -  "errorCount",
        -  "totalVulns",
        -  "worstSeverity"
        -]New value: +[
        +  "totalPackages",
        +  "vulnerableCount",
        +  "cleanCount",
        +  "truncatedCount",
        +  "errorCount",
        +  "totalVulns",
        +  "worstSeverity"
        +]
    • Changedosv_query_package11 fields changed
      • addedOutput schema / properties / truncated
        Added value: +{
        +  "description": "True when OSV returned more result pages than the fetch cap could follow — the vulnerability list may be INCOMPLETE. A truncated empty list is NOT a clean result; raise OSV_QUERY_MAX_PAGES or narrow the query.",
        +  "type": "boolean"
        +}
      • changedOutput schema / properties / vulns / description
        Previous value: -"Vulnerabilities matching this package version. Empty array means no known vulnerabilities."New value: +"Vulnerabilities matching this package version. An empty array means no known vulnerabilities ONLY when truncated is false."
      • changedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / ecosystem / description
        Previous value: -"Affected package ecosystem."New value: +"Affected package ecosystem. Empty for source-only advisory ranges."
      • addedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / events
        Added value: +{
        +  "description": "Ordered event boundaries for this range — the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.",
        +  "items": {
        +    "additionalProperties": false,
        +    "description": "One ordered range event.",
        +    "properties": {
        +      "type": {
        +        "description": "Event boundary type: \"introduced\", \"fixed\", \"last_affected\", or \"limit\".",
        +        "type": "string"
        +      },
        +      "value": {
        +        "description": "Version string or commit identifier at this boundary.",
        +        "type": "string"
        +      }
        +    },
        +    "required": [
        +      "type",
        +      "value"
        +    ],
        +    "type": "object"
        +  },
        +  "type": "array"
        +}
      • changedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / fixed / description
        Previous value: -"First safe version — the version to upgrade to."New value: +"First safe version — the version to upgrade to (convenience view — see events[])."
      • changedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / introduced / description
        Previous value: -"First affected version."New value: +"First affected version (convenience view — see events[])."
      • changedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / lastAffected / description
        Previous value: -"Last affected version. Present when no fix exists."New value: +"Last affected version. Present when no fix exists (convenience view — see events[])."
      • changedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / packageName / description
        Previous value: -"Affected package name (may differ from queried name for umbrella advisories)."New value: +"Affected package name (may differ from queried name for umbrella advisories). Empty for source-only advisory ranges."
      • addedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / repo
        Added value: +{
        +  "description": "Source repository URL for GIT ranges. Absent on version ranges.",
        +  "type": "string"
        +}
      • addedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / versions
        Added value: +{
        +  "description": "Explicit affected versions listed on this package entry. Absent or empty when affected versions are expressed only as ranges.",
        +  "items": {
        +    "description": "An explicitly-listed affected version.",
        +    "type": "string"
        +  },
        +  "type": "array"
        +}
      • changedOutput schema / required
        Previous value: -[
        -  "vulns",
        -  "queryMeta"
        -]New value: +[
        +  "vulns",
        +  "truncated",
        +  "queryMeta"
        +]
  6. 2 tool updates
    • Changedosv_query_batch2 fields changed
      • addedOutput schema / properties / effectiveQuery
        Added value: +{
        +  "description": "Compact scan summary (package and outcome counts), echoed on edge-case batches for content-only clients.",
        +  "type": "string"
        +}
      • addedOutput schema / properties / notice
        Added value: +{
        +  "description": "Present on all-clean or all-errors batches — the aggregate outcome for content-only clients.",
        +  "type": "string"
        +}
    • Changedosv_query_package2 fields changed
      • addedOutput schema / properties / effectiveQuery
        Added value: +{
        +  "description": "The package@version (ecosystem) tuple as queried, echoed for content-only clients.",
        +  "type": "string"
        +}
      • addedOutput schema / properties / notice
        Added value: +{
        +  "description": "Present on the clean path — confirms no known vulnerabilities for the queried package.",
        +  "type": "string"
        +}
  7. 1 tool update
    • Changedosv_list_ecosystems1 field changed
      • changedOutput schema / properties / ecosystems / description
        Previous value: -"Supported ecosystem identifier strings. These are case-sensitive exact matches required by the ecosystem parameter of osv_query and osv_query_batch."New value: +"Supported ecosystem identifier strings. These are case-sensitive exact matches required by the ecosystem parameter of osv_query_package and osv_query_batch."
  8. 2 tool updates
    • Removedosv_query
    • Addedosv_query_package
  9. 1 tool update
    • Changedosv_query_batch2 fields changed
      • removedInput schema / properties / canvas_id
        Removed value: -{
        -  "description": "Reuse an existing DataCanvas table token to append results. Omit to create a new canvas. Only relevant when package count >= 200.",
        -  "type": "string"
        -}
      • removedOutput schema / properties / canvas_id
        Removed value: -{
        -  "description": "DataCanvas table token. Present when the package count is >= 200 or a canvas_id was provided. Use to run SQL queries across the full result set via the canvas tools.",
        -  "type": "string"
        -}
  10. 4 tool updates
    • First observedosv_get_vulnerability
    • First observedosv_list_ecosystems
    • First observedosv_query
    • First observedosv_query_batch

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    F
    maintenance
    Enables auditing npm, pip, and other package dependencies for known CVEs via the OSV database, with tools to scan manifests, query individual packages, and integrate into CI/CD workflows.
    456 npm
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A local MCP server that scans repository dependencies for known vulnerabilities (CVEs) using OSV.dev, enriches findings with NVD and CISA KEV data, and supports triage, remediation, and accepted risk management directly from an AI coding assistant.
    6
    30 npm
    1
    MIT
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.