Enables auditing npm, pip, and other package dependencies for known CVEs via the OSV database, with tools to scan manifests, query individual packages, and integrate into CI/CD workflows.
Enables AI agents to look up known open-source vulnerabilities in the OSV.dev database, covering individual packages and versions, specific git commits, single vulnerability IDs, and batch SBOM-style dependency scans. Queries are keyless and return compact summaries or full vulnerability details with affected ranges and references.