get_dependency_vulnerabilities
Checks Maven dependencies for known vulnerabilities using OSV.dev, returning CVEs and advisory upgrade candidates for pinned versions.
Instructions
Check dependencies for known vulnerabilities using the OSV.dev database. Each dependency requires a pinned version — OSV lookups are version-specific and version-less coordinates are not queried. An empty vulnerabilities list means no known CVE/GHSA advisory was found for that coordinate+version in OSV.dev; it is NOT a safety guarantee (OSV coverage is incomplete and reporting lags real-world disclosure). When ≥1 vulnerability is found, a per-dependency safeUpgrade candidate is synthesized from the already-fetched fixed-version data (the highest fixed version across all known CVEs) — ADVISORY ONLY, a candidate to verify, never a guaranteed-safe pin; fixesAllKnown is false when at least one CVE has no known fix.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| projectPath | No | Project root used to resolve declared repositories. Defaults to the current working directory. | |
| dependencies | Yes | Dependencies to check, each with a pinned version (required). |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| results | Yes | ||
| capabilityUnavailable | No |