PlannedPlanned for Package Risk
OSV.dev open source vulnerability database
What it is
A database of open source package vulnerabilities in the OSV format, covering npm, PyPI, Go, Maven, crates.io, NuGet, Linux distributions and more.
Publisher and URL
Licence
Each upstream database carries its own licence. Those we plan to use allow commercial reuse with attribution or none: GitHub Advisory Database (CC-BY 4.0), PyPI Advisory Database (CC-BY 4.0), Go Vulnerability Database (CC-BY 4.0), Rust Advisory Database (CC0 1.0), Global Security Database (CC0 1.0), OSS-Fuzz (CC-BY 4.0), OpenSSF Malicious Packages (Apache 2.0), Python Software Foundation (CC-BY 4.0).
Ubuntu's data is licensed CC-BY-SA 4.0 and is not included at present. We will record the upstream source of every record and attribute it.
Update cadence
Continuous. We plan to read the per-ecosystem change lists each night.
Fields we use
id, aliases (CVE and GHSA), modified, summary, affected packages with ecosystems, ranges and versions, severity, references, upstream source.
Known gaps
- Covers open source packages, not commercial products or operating systems outside the listed distributions.
How Stackbyte will use it
Will be the core of Package Risk, including the OpenSSF malicious packages feed, and will link CVEs to affected packages in CVE Triage.