get_vulnerability_paths
Trace each vulnerable transitive Maven dependency back to the direct dependency that pulls it in by mapping shortest root-to-node paths using deps.dev and OSV.dev.
Instructions
Show the dependency path from a project root Maven GAV to each vulnerable transitive node. Fetches the deps.dev transitive graph, checks every unique node for known CVE/GHSA advisories via OSV.dev, and returns the shortest root-to-node path for each vulnerable dependency found — so a CVE deep in the tree can be traced back to which direct dependency pulls it in. An empty vulnerabilityPaths list means no known vulnerability was found in the graph; it is not a safety guarantee (same OSV coverage caveat as get_dependency_vulnerabilities). Partial results are flagged when deps.dev/OSV is unreachable, the graph is truncated by the node cap, or the unique-dependency count is truncated before querying OSV.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| groupId | Yes | Maven group ID of the project root | |
| version | Yes | Maven version of the project root | |
| artifactId | Yes | Maven artifact ID of the project root |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| notes | No | ||
| groupId | Yes | ||
| partial | Yes | ||
| version | Yes | ||
| truncated | Yes | ||
| artifactId | Yes | ||
| vulnerabilityPaths | Yes | ||
| capabilityUnavailable | No | ||
| unreachableVulnerabilities | No |