# Open Source Vulnerability Scraper (OSV.dev) (`chrisp1211/vulnerability-scraper-max`) Actor

Look up open-source security vulnerabilities from OSV.dev for any package across npm, PyPI, Go, Maven, crates and more. Returns CVE IDs, severity, summary and references. No API key. Pay per vulnerability; empty runs free.

- **URL**: https://apify.com/chrisp1211/vulnerability-scraper-max.md
- **Developed by:** [Christian Pichichero](https://apify.com/chrisp1211) (community)
- **Categories:** Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$1.00 / 1,000 records

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are a software tools running on the Apify platform, for all kinds of web data extraction and automation use cases.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

In JavaScript/TypeScript projects, use official [JavaScript/TypeScript client](https://docs.apify.com/api/client/js/docs.md):

```bash
npm install apify-client
```

In Python projects, use official [Python client library](https://docs.apify.com/api/client/python/docs.md):

```bash
pip install apify-client
```

In shell scripts, use [Apify CLI](https://docs.apify.com/cli/docs.md):

````bash
# MacOS / Linux
curl -fsSL https://apify.com/install-cli.sh | bash
# Windows
irm https://apify.com/install-cli.ps1 | iex
```bash

In AI frameworks, you might use the [Apify MCP server](https://docs.apify.com/integrations/mcp.md).

If your project is in a different language, use the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).


# README

## Open Source Vulnerability Scraper (OSV.dev)

**Open Source Vulnerability Scraper (OSV.dev)** — a fast, reliable vulnerability scraper that needs **no API key**. You pay only for the results you get: failed or empty runs are always free.

This vulnerability scraper runs on the [Apify platform](https://apify.com), so you can call it from the API, run it on a schedule, or export results to JSON, CSV, Excel, or Google Sheets.

### What this scraper does

- Extracts structured **vulnerability** data with no browser or API key required
- Returns clean JSON, one record per result — ready for sheets, databases, or apps
- Pay-per-result pricing: you are never charged for a run that returns nothing
- Runs on demand or on a schedule, and integrates with 5,000+ apps via the Apify API and webhooks

### What data you get

Each result record includes fields such as:

- **Id** (`id`) — e.g. `"GHSA-29mw-wpgm-hmr9"`
- **Summary** (`summary`) — e.g. `"Regular Expression Denial of Service (ReDoS) in lodash"`
- **Details** (`details`) — e.g. `"All versions of package lodash prior to 4.17.21 are vuln...`
- **Aliases** (`aliases`) — e.g. `["CVE-2020-28500"]`
- **Cve Ids** (`cveIds`) — e.g. `["CVE-2020-28500"]`
- **Package Name** (`packageName`) — e.g. `"lodash"`
- **Ecosystem** (`ecosystem`) — e.g. `"npm"`
- **Severity** (`severity`) — e.g. `"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"`
- **Severity Rating** (`severityRating`) — e.g. `"MODERATE"`
- **Cvss Vector** (`cvssVector`) — e.g. `"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"`
- **Cwe Ids** (`cweIds`) — e.g. `["CWE-1333", "CWE-400"]`
- **Published** (`published`) — e.g. `"2022-01-06T20:30:46Z"`
- **Modified** (`modified`) — e.g. `"2025-09-29T21:12:31.102523Z"`
- **Affected Packages** (`affectedPackages`) — e.g. `["lodash", "lodash-es", "lodash.trimend", "lodash.trim", ...`
- **References** (`references`) — e.g. `["https://nvd.nist.gov/vuln/detail/CVE-2020-28500", "http...`

### Input

| Field | Type | Description |
|---|---|---|
| `packages` | array | Package names to look up vulnerabilities for (one query per name), e.g. lodash, express. Names must match t... |
| `ecosystem` | string | Package ecosystem the names belong to. Applied to every package in this run. |
| `version` | string | Optional exact package version. When set, results are narrowed to vulnerabilities affecting that specific v... |
| `maxResults` | integer | Maximum number of vulnerability records to return per package. |

### Example output

```json
{
  "type": "vulnerability",
  "id": "GHSA-29mw-wpgm-hmr9",
  "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
  "details": "All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.",
  "aliases": [
    "CVE-2020-28500"
  ],
  "cveIds": [
    "CVE-2020-28500"
  ],
  "packageName": "lodash",
  "ecosystem": "npm",
  "severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "severityRating": "MODERATE",
  "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cweIds": [
    "CWE-1333",
    "CWE-400"
  ],
  "published": "2022-01-06T20:30:46Z",
  "modified": "2025-09-29T21:12:31.102523Z",
  "affectedPackages": [
    "lodash",
    "lodash-es",
    "lodash.trimend",
    "lodash.trim",
    "lodash-rails"
  ],
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2020-28500",
    "https://github.com/lodash/lodash"
  ],
  "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9",
  "query": "lodash (npm)",
  "scrapedAt": "2026-07-11T00:00:00Z"
}
````

### Use cases

- Monitor packages, repos, and dependencies
- Automate security and license audits
- Build developer dashboards and alerts
- Enrich internal tools and integrations

### Run it as a monitor (alerts on new vulnerability)

Schedule this vulnerability scraper to run automatically — hourly, daily, or on any cron schedule — with the built-in [Apify Scheduler](https://docs.apify.com/platform/schedules), and have results pushed to you by **webhook, email, Slack, or your own app** the moment they're ready. It's the easiest way to **monitor vulnerability for changes over time** and get alerted the instant something new appears — no manual runs. Because pricing is per result, a scheduled monitor only ever charges you for the data each run actually returns.

### Pricing

This actor uses **pay-per-result** pricing at **$0.0006 per record**. There is no monthly fee and no start fee — and **empty or failed runs cost $0**, so you only ever pay for data you actually receive.

### Frequently asked questions

**Do I need an API key or account for the source?** No. This vulnerability scraper works out of the box with no API key required.

**What happens if a run returns no results?** You are not charged. Billing is per result, so empty or failed runs are free.

**Can I run the vulnerability scraper on a schedule?** Yes. Use the Apify Scheduler to run it hourly, daily, or on any cron schedule, and get results by webhook or API.

**What export formats are supported?** Results can be exported as JSON, CSV, Excel, HTML, or pushed to Google Sheets, a database, or your own app via the Apify API.

**Is the data structured?** Yes. Every vulnerability result is a clean, flat JSON record you can use immediately.

# Actor input Schema

## `packages` (type: `array`):

Package names to look up vulnerabilities for (one query per name), e.g. lodash, express. Names must match the selected ecosystem.

## `ecosystem` (type: `string`):

Package ecosystem the names belong to. Applied to every package in this run.

## `version` (type: `string`):

Optional exact package version. When set, results are narrowed to vulnerabilities affecting that specific version.

## `maxResults` (type: `integer`):

Maximum number of vulnerability records to return per package.

## `maxCostUsd` (type: `integer`):

HARD budget cap. The run stops cleanly before exceeding this.

## `proxyConfiguration` (type: `object`):

This is an open API; no proxy needed. Default is fine.

## Actor input object example

```json
{
  "packages": [
    "lodash"
  ],
  "ecosystem": "npm",
  "maxResults": 50,
  "proxyConfiguration": {
    "useApifyProxy": false
  }
}
```

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "packages": [
        "lodash"
    ],
    "proxyConfiguration": {
        "useApifyProxy": false
    }
};

// Run the Actor and wait for it to finish
const run = await client.actor("chrisp1211/vulnerability-scraper-max").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "packages": ["lodash"],
    "proxyConfiguration": { "useApifyProxy": False },
}

# Run the Actor and wait for it to finish
run = client.actor("chrisp1211/vulnerability-scraper-max").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "packages": [
    "lodash"
  ],
  "proxyConfiguration": {
    "useApifyProxy": false
  }
}' |
apify call chrisp1211/vulnerability-scraper-max --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=chrisp1211/vulnerability-scraper-max",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

```json
{
    "openapi": "3.0.1",
    "info": {
        "title": "Open Source Vulnerability Scraper (OSV.dev)",
        "description": "Look up open-source security vulnerabilities from OSV.dev for any package across npm, PyPI, Go, Maven, crates and more. Returns CVE IDs, severity, summary and references. No API key. Pay per vulnerability; empty runs free.",
        "version": "0.1",
        "x-build-id": "htRbnqWYXvirwmRhH"
    },
    "servers": [
        {
            "url": "https://api.apify.com/v2"
        }
    ],
    "paths": {
        "/acts/chrisp1211~vulnerability-scraper-max/run-sync-get-dataset-items": {
            "post": {
                "operationId": "run-sync-get-dataset-items-chrisp1211-vulnerability-scraper-max",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        },
        "/acts/chrisp1211~vulnerability-scraper-max/runs": {
            "post": {
                "operationId": "runs-sync-chrisp1211-vulnerability-scraper-max",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor and returns information about the initiated run in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/runsResponseSchema"
                                }
                            }
                        }
                    }
                }
            }
        },
        "/acts/chrisp1211~vulnerability-scraper-max/run-sync": {
            "post": {
                "operationId": "run-sync-chrisp1211-vulnerability-scraper-max",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        }
    },
    "components": {
        "schemas": {
            "inputSchema": {
                "type": "object",
                "properties": {
                    "packages": {
                        "title": "Package names",
                        "type": "array",
                        "description": "Package names to look up vulnerabilities for (one query per name), e.g. lodash, express. Names must match the selected ecosystem.",
                        "items": {
                            "type": "string"
                        }
                    },
                    "ecosystem": {
                        "title": "Ecosystem",
                        "enum": [
                            "npm",
                            "PyPI",
                            "Go",
                            "Maven",
                            "crates.io",
                            "RubyGems",
                            "NuGet",
                            "Packagist",
                            "Pub",
                            "Hex"
                        ],
                        "type": "string",
                        "description": "Package ecosystem the names belong to. Applied to every package in this run.",
                        "default": "npm"
                    },
                    "version": {
                        "title": "Version (optional)",
                        "type": "string",
                        "description": "Optional exact package version. When set, results are narrowed to vulnerabilities affecting that specific version."
                    },
                    "maxResults": {
                        "title": "Max results per package",
                        "minimum": 1,
                        "type": "integer",
                        "description": "Maximum number of vulnerability records to return per package.",
                        "default": 50
                    },
                    "maxCostUsd": {
                        "title": "Max cost per run (USD)",
                        "minimum": 1,
                        "type": "integer",
                        "description": "HARD budget cap. The run stops cleanly before exceeding this."
                    },
                    "proxyConfiguration": {
                        "title": "Proxy",
                        "type": "object",
                        "description": "This is an open API; no proxy needed. Default is fine.",
                        "default": {
                            "useApifyProxy": false
                        }
                    }
                }
            },
            "runsResponseSchema": {
                "type": "object",
                "properties": {
                    "data": {
                        "type": "object",
                        "properties": {
                            "id": {
                                "type": "string"
                            },
                            "actId": {
                                "type": "string"
                            },
                            "userId": {
                                "type": "string"
                            },
                            "startedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "finishedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "status": {
                                "type": "string",
                                "example": "READY"
                            },
                            "meta": {
                                "type": "object",
                                "properties": {
                                    "origin": {
                                        "type": "string",
                                        "example": "API"
                                    },
                                    "userAgent": {
                                        "type": "string"
                                    }
                                }
                            },
                            "stats": {
                                "type": "object",
                                "properties": {
                                    "inputBodyLen": {
                                        "type": "integer",
                                        "example": 2000
                                    },
                                    "rebootCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "restartCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "resurrectCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "computeUnits": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "options": {
                                "type": "object",
                                "properties": {
                                    "build": {
                                        "type": "string",
                                        "example": "latest"
                                    },
                                    "timeoutSecs": {
                                        "type": "integer",
                                        "example": 300
                                    },
                                    "memoryMbytes": {
                                        "type": "integer",
                                        "example": 1024
                                    },
                                    "diskMbytes": {
                                        "type": "integer",
                                        "example": 2048
                                    }
                                }
                            },
                            "buildId": {
                                "type": "string"
                            },
                            "defaultKeyValueStoreId": {
                                "type": "string"
                            },
                            "defaultDatasetId": {
                                "type": "string"
                            },
                            "defaultRequestQueueId": {
                                "type": "string"
                            },
                            "buildNumber": {
                                "type": "string",
                                "example": "1.0.0"
                            },
                            "containerUrl": {
                                "type": "string"
                            },
                            "usage": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "integer",
                                        "example": 1
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "usageTotalUsd": {
                                "type": "number",
                                "example": 0.00005
                            },
                            "usageUsd": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "number",
                                        "example": 0.00005
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            }
                        }
                    }
                }
            }
        }
    }
}
```
