OpenSSF · Capability
OSV (Open Source Vulnerabilities) API
OSV is a distributed open source vulnerability database and triage infrastructure project hosted by the Open Source Security Foundation (OpenSSF). The OSV API exposes vulnerability records keyed to specific package versions or commits across multiple ecosystems (npm, PyPI, Maven, Go, NuGet, RubyGems, Cargo, Packagist, Hex, OSS-Fuzz, Linux, Android, GitHub Actions, etc.).
What You Can Do
POST
Queryvulnerabilities
— Query vulnerabilities for a package or commit
/v1/query
POST
Queryvulnerabilitiesbatch
— Batched vulnerability query
/v1/querybatch
GET
Getvulnerability
— Get vulnerability by OSV ID
/v1/vulns/{id}
POST
Determineversion
— Determine probable versions of a C/C++ project (experimental)
/v1experimental/determineversion
GET
Importfindings
— Import-time quality check findings (experimental)
/v1experimental/importfindings
MCP Tools
queryvulnerabilities
Query vulnerabilities for a package or commit
queryvulnerabilitiesbatch
Batched vulnerability query
getvulnerability
Get vulnerability by OSV ID
read-only
idempotent
determineversion
Determine probable versions of a C/C++ project (experimental)
importfindings
Import-time quality check findings (experimental)
read-only
idempotent