Check a package
check_packageCheck one open-source package (npm, PyPI, Go, Maven, crates.io or NuGet) for safety and freshness. Returns a malicious-package flag (from OSV MAL- and malware advisories), known vulnerabilities with severity and the version that fixes each, the minimum version that clears all of them, the latest stable version, whether the given version is outdated or deprecated, licences, last release date, and the linked repository's OpenSSF Scorecard. If no version is given, the latest version is checked. Use when the user asks "is safe?", "is it malware?", "which version should I use?", "should I upgrade?", or about a package's known CVEs, and before recommending any package or version to install (npm install, pip install, go get, cargo add, etc.). Data comes from OSV.dev and deps.dev; newly published malware may not be listed yet.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Package name, e.g. lodash, @types/node, requests, github.com/gin-gonic/gin, org.apache.logging.log4j:log4j-core, serde, Newtonsoft.Json | |
| version | No | Optional exact version to check, e.g. 4.17.15. Omit to check the latest release | |
| ecosystem | Yes | Package ecosystem: npm, PyPI, Go, Maven, crates.io or NuGet (aliases like pip, python, cargo, rust, golang, java, dotnet also work) |