Go to example tasks

Check a package-lock.json for known CVEs

Paste package-lock.json → exact CVE/GHSA, CVSS, fixed version per dependency — verified against installed version. (~160)

Try for free
Container CVE Matcher
Container CVE Matchercodeclouds/container-cve-matcher
Record type
Scanned input
Package
Ecosystem
+16 fields
Text
Number
Boolean
List
Object

Input

Inline lockfiles / SBOMs
Filename(required):package-lock.json
Content(required):{"lockfileVersion":3,"packages":{"":{"name":"my-app"},"node_modules/lodash":{"version":"4.17.15"}}}

Output fields

Record type
Scanned input
Package
Ecosystem
Version
Installed version
Ecosystem supported
Checked against OSV
Matches
OSV/GHSA ID
CVE ID
Severity
CVSS score
Patched in
Summary
Highest severity (run)
Total matches (run)
Dependencies checked (run)
Dependency note
Run error

How it works

Sign up on Apify01

Create your Apify account to access the Container CVE Matcher.

Start the run02

The Actor will start running based on the input automatically.

Receive the output03

Monitor the progress in real-time. You will be notified as soon as your dataset is complete and ready for review.

Integrate into your workflow04

The final output is delivered in JSON, CSV, or Excel format, ready to be plugged into your workflow.

Image

Integrate Actor directly into your workflow

Choose from one of 100+ integration options we provide or integrate via API

Webhook

Webhook

n8n

n8n

Make

Make

Zapier

Zapier

Airbyte

Airbyte

Keboola

Keboola

IFTTT

IFTTT

Hubspot

Hubspot

GDrive

GDrive

Gmail

Gmail

Apify MCP

Apify MCP

GitHub

GitHub

Slack

Slack

LangChain

LangChain

LlamaIndex

LlamaIndex

Flowise

Flowise

Pinecone

Pinecone

OpenAI

OpenAI

Mastra

Mastra

Clay

Clay