Container CVE Matcher
Under maintenancePricing
from $1.00 / 1,000 dependency cve checkeds
Container CVE Matcher
Under maintenanceMatches a dependency list, lockfile, or SBOM against OSV.dev to report
Container CVE Matcher
Under maintenancePricing
from $1.00 / 1,000 dependency cve checkeds
Matches a dependency list, lockfile, or SBOM against OSV.dev to report
You can access the Container CVE Matcher programmatically from your own applications by using the Apify API. You can also choose the language preference from below. To use the Apify API, you’ll need an Apify account and your API token, found in API & Integrations in Apify Console.
{ "openapi": "3.0.1", "info": { "version": "0.1", "x-build-id": "PXgQnLbQFqdMcbtgS" }, "servers": [ { "url": "https://api.apify.com/v2" } ], "paths": { "/acts/codeclouds~container-cve-matcher/run-sync-get-dataset-items": { "post": { "operationId": "run-sync-get-dataset-items-codeclouds-container-cve-matcher", "x-openai-isConsequential": false, "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.", "tags": [ "Run Actor" ], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/inputSchema" } } } }, "parameters": [ { "name": "token", "in": "query", "required": true, "schema": { "type": "string" }, "description": "Enter your Apify token here" } ], "responses": { "200": { "description": "OK" } } } }, "/acts/codeclouds~container-cve-matcher/runs": { "post": { "operationId": "runs-sync-codeclouds-container-cve-matcher", "x-openai-isConsequential": false, "summary": "Executes an Actor and returns information about the initiated run in response.", "tags": [ "Run Actor" ], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/inputSchema" } } } }, "parameters": [ { "name": "token", "in": "query", "required": true, "schema": { "type": "string" }, "description": "Enter your Apify token here" } ], "responses": { "200": { "description": "OK", "content": { "application/json": { "schema": { "$ref": "#/components/schemas/runsResponseSchema" } } } } } } }, "/acts/codeclouds~container-cve-matcher/run-sync": { "post": { "operationId": "run-sync-codeclouds-container-cve-matcher", "x-openai-isConsequential": false, "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.", "tags": [ "Run Actor" ], "requestBody": { "required": true, "content": { "application/json": { "schema": { "$ref": "#/components/schemas/inputSchema" } } } }, "parameters": [ { "name": "token", "in": "query", "required": true, "schema": { "type": "string" }, "description": "Enter your Apify token here" } ], "responses": { "200": { "description": "OK" } } } } }, "components": { "schemas": { "inputSchema": { "type": "object", "properties": { "repoUrl": { "title": "Repository URL", "type": "string", "description": "Public git repository to clone and scan for lockfiles/SBOMs (https:// or http:// only). Provide this, or fill in \"manifests\"/\"dependencies\" below, or any combination. Example: \"https://github.com/expressjs/express.git\"." }, "gitRef": { "title": "Git branch / tag / commit", "type": "string", "description": "Branch, tag, or commit to check out. Leave empty to use the repository's default branch." }, "manifests": { "title": "Inline lockfiles / SBOMs", "type": "array", "description": "One or more dependency files pasted directly, instead of (or in addition to) a repository URL. Each item needs a \"filename\" (used to detect the format: \"package-lock.json\", \"requirements.txt\", \"Pipfile.lock\", or a CycloneDX/SPDX SBOM .json file) and its \"content\".", "items": { "type": "object", "properties": { "filename": { "title": "Filename", "type": "string", "description": "E.g. \"package-lock.json\", \"requirements.txt\", \"Pipfile.lock\", or \"sbom.json\"." }, "content": { "title": "Content", "type": "string", "description": "The full text content of the file." } }, "required": [ "filename", "content" ] }, "default": [] }, "dependencies": { "title": "Direct dependency list", "type": "array", "description": "A flat package+version list, for callers (e.g. an AI agent) that already know exactly what's installed and don't need lockfile/SBOM parsing. Each item needs a \"name\" and exact \"version\"; \"ecosystem\" defaults to \"npm\" (also supports \"PyPI\").", "items": { "type": "object", "properties": { "name": { "title": "Package name", "type": "string", "description": "E.g. \"lodash\" or \"flask\"." }, "version": { "title": "Exact installed version", "type": "string", "description": "E.g. \"4.17.15\". Must be an exact version, not a range — this actor matches the exact installed version, not a range." }, "ecosystem": { "title": "Ecosystem", "type": "string", "description": "\"npm\" or \"PyPI\". Defaults to \"npm\" when omitted." } }, "required": [ "name", "version" ] }, "default": [] }, "maxDependencies": { "title": "Max dependencies to check", "minimum": 1, "maximum": 1000, "type": "integer", "description": "Safety cap on how many dependencies get a live OSV.dev lookup in one run. Example: 300.", "default": 300 } } }, "runsResponseSchema": { "type": "object", "properties": { "data": { "type": "object", "properties": { "id": { "type": "string" }, "actId": { "type": "string" }, "userId": { "type": "string" }, "startedAt": { "type": "string", "format": "date-time", "example": "2025-01-08T00:00:00.000Z" }, "finishedAt": { "type": "string", "format": "date-time", "example": "2025-01-08T00:00:00.000Z" }, "status": { "type": "string", "example": "READY" }, "meta": { "type": "object", "properties": { "origin": { "type": "string", "example": "API" }, "userAgent": { "type": "string" } } }, "stats": { "type": "object", "properties": { "inputBodyLen": { "type": "integer", "example": 2000 }, "rebootCount": { "type": "integer", "example": 0 }, "restartCount": { "type": "integer", "example": 0 }, "resurrectCount": { "type": "integer", "example": 0 }, "computeUnits": { "type": "integer", "example": 0 } } }, "options": { "type": "object", "properties": { "build": { "type": "string", "example": "latest" }, "timeoutSecs": { "type": "integer", "example": 300 }, "memoryMbytes": { "type": "integer", "example": 1024 }, "diskMbytes": { "type": "integer", "example": 2048 } } }, "buildId": { "type": "string" }, "defaultKeyValueStoreId": { "type": "string" }, "defaultDatasetId": { "type": "string" }, "defaultRequestQueueId": { "type": "string" }, "buildNumber": { "type": "string", "example": "1.0.0" }, "containerUrl": { "type": "string" }, "usage": { "type": "object", "properties": { "ACTOR_COMPUTE_UNITS": { "type": "integer", "example": 0 }, "DATASET_READS": { "type": "integer", "example": 0 }, "DATASET_WRITES": { "type": "integer", "example": 0 }, "KEY_VALUE_STORE_READS": { "type": "integer", "example": 0 }, "KEY_VALUE_STORE_WRITES": { "type": "integer", "example": 1 }, "KEY_VALUE_STORE_LISTS": { "type": "integer", "example": 0 }, "REQUEST_QUEUE_READS": { "type": "integer", "example": 0 }, "REQUEST_QUEUE_WRITES": { "type": "integer", "example": 0 }, "DATA_TRANSFER_INTERNAL_GBYTES": { "type": "integer", "example": 0 }, "DATA_TRANSFER_EXTERNAL_GBYTES": { "type": "integer", "example": 0 }, "PROXY_RESIDENTIAL_TRANSFER_GBYTES": { "type": "integer", "example": 0 }, "PROXY_SERPS": { "type": "integer", "example": 0 } } }, "usageTotalUsd": { "type": "number", "example": 0.00005 }, "usageUsd": { "type": "object", "properties": { "ACTOR_COMPUTE_UNITS": { "type": "integer", "example": 0 }, "DATASET_READS": { "type": "integer", "example": 0 }, "DATASET_WRITES": { "type": "integer", "example": 0 }, "KEY_VALUE_STORE_READS": { "type": "integer", "example": 0 }, "KEY_VALUE_STORE_WRITES": { "type": "number", "example": 0.00005 }, "KEY_VALUE_STORE_LISTS": { "type": "integer", "example": 0 }, "REQUEST_QUEUE_READS": { "type": "integer", "example": 0 }, "REQUEST_QUEUE_WRITES": { "type": "integer", "example": 0 }, "DATA_TRANSFER_INTERNAL_GBYTES": { "type": "integer", "example": 0 }, "DATA_TRANSFER_EXTERNAL_GBYTES": { "type": "integer", "example": 0 }, "PROXY_RESIDENTIAL_TRANSFER_GBYTES": { "type": "integer", "example": 0 }, "PROXY_SERPS": { "type": "integer", "example": 0 } } } } } } } } }}OpenAPI is a standard for designing and describing RESTful APIs, allowing developers to define API structure, endpoints, and data formats in a machine-readable way. It simplifies API development, integration, and documentation.
OpenAPI is effective when used with AI agents and GPTs by standardizing how these systems interact with various APIs, for reliable integrations and efficient communication.
By defining machine-readable API specifications, OpenAPI allows AI models like GPTs to understand and use varied data sources, improving accuracy. This accelerates development, reduces errors, and provides context-aware responses, making OpenAPI a core component for AI applications.
You can download the OpenAPI definitions for Container CVE Matcher from the options below:
If you’d like to learn more about how OpenAPI powers GPTs, read our blog post.
You can also check out our other API clients: