Skip to content
All data sources

PlannedPlanned for Package Risk

OSV.dev open source vulnerability database

What it is

A database of open source package vulnerabilities in the OSV format, covering npm, PyPI, Go, Maven, crates.io, NuGet, Linux distributions and more.

Publisher and URL

Google, with data from upstream advisory databases.

Licence

Each upstream database carries its own licence. Those we plan to use allow commercial reuse with attribution or none: GitHub Advisory Database (CC-BY 4.0), PyPI Advisory Database (CC-BY 4.0), Go Vulnerability Database (CC-BY 4.0), Rust Advisory Database (CC0 1.0), Global Security Database (CC0 1.0), OSS-Fuzz (CC-BY 4.0), OpenSSF Malicious Packages (Apache 2.0), Python Software Foundation (CC-BY 4.0).

Ubuntu's data is licensed CC-BY-SA 4.0 and is not included at present. We will record the upstream source of every record and attribute it.

OSV data sources and licences

Update cadence

Continuous. We plan to read the per-ecosystem change lists each night.

Fields we use

id, aliases (CVE and GHSA), modified, summary, affected packages with ecosystems, ranges and versions, severity, references, upstream source.

Known gaps

  • Covers open source packages, not commercial products or operating systems outside the listed distributions.

How Stackbyte will use it

Will be the core of Package Risk, including the OpenSSF malicious packages feed, and will link CVEs to affected packages in CVE Triage.

Attribution

Vulnerability data from OSV.dev and its upstream databases; see stackbyte.app/sources/osv.

Last checked: by Stackbyte Engineering. Spotted something out of date? Tell us.