OpenSSF · Capability
OSV (Open Source Vulnerabilities) API
OSV (Open Source Vulnerabilities) API. 5 operations. Lead operation: Query vulnerabilities for a package or commit. Self-contained Naftiko capability covering one Openssf business surface.
What You Can Do
POST
Queryvulnerabilities
— Query vulnerabilities for a package or commit
/v1/v1/query
POST
Queryvulnerabilitiesbatch
— Batched vulnerability query
/v1/v1/querybatch
GET
Getvulnerability
— Get vulnerability by OSV ID
/v1/v1/vulns/{id}
POST
Determineversion
— Determine probable versions of a C/C++ project (experimental)
/v1/v1experimental/determineversion
GET
Importfindings
— Import-time quality check findings (experimental)
/v1/v1experimental/importfindings
MCP Tools
query-vulnerabilities-package-commit
Query vulnerabilities for a package or commit
read-only
batched-vulnerability-query
Batched vulnerability query
read-only
get-vulnerability-osv-id
Get vulnerability by OSV ID
read-only
idempotent
determine-probable-versions-c-c
Determine probable versions of a C/C++ project (experimental)
import-time-quality-check-findings
Import-time quality check findings (experimental)
read-only
idempotent