Overview
Query the OSV (Open Source Vulnerabilities) API to check packages for known vulnerabilities.
Depends On
Acceptance Criteria
OSV API Format
curl -X POST https://api.osv.dev/v1/query -d '{
"package": {"name": "lodash", "ecosystem": "npm"},
"version": "4.17.0"
}'
Response Structure
- vulns[].id (CVE/GHSA ID)
- vulns[].summary
- vulns[].severity[].score (CVSS)
- vulns[].affected[].ranges[].events (fixed version)
Priority: P0
Overview
Query the OSV (Open Source Vulnerabilities) API to check packages for known vulnerabilities.
Depends On
Acceptance Criteria
OSV API Format
Response Structure
Priority: P0