Go to example tasks
Check a package-lock.json for known CVEs
Created by
Dennis
Paste package-lock.json → exact CVE/GHSA, CVSS, fixed version per dependency — verified against installed version. (~160)
Container CVE Matchercodeclouds/container-cve-matcher
Record type
Scanned input
Package
Ecosystem
+16 fieldsTextNumberBooleanListObject
Input
Inline lockfiles / SBOMs
Filename(required):package-lock.json
Content(required):{"lockfileVersion":3,"packages":{"":{"name":"my-app"},"node_modules/lodash":{"version":"4.17.15"}}}
Output fields
Record type
Scanned input
Package
Ecosystem
Version
Installed version
Ecosystem supported
Checked against OSV
Matches
OSV/GHSA ID
CVE ID
Severity
CVSS score
Patched in
Summary
Highest severity (run)
Total matches (run)
Dependencies checked (run)
Dependency note
Run error
Sign up on Apify01
Create your Apify account to access the Container CVE Matcher.
Start the run02
The Actor will start running based on the input automatically.
Receive the output03
Monitor the progress in real-time. You will be notified as soon as your dataset is complete and ready for review.
Integrate into your workflow04
The final output is delivered in JSON, CSV, or Excel format, ready to be plugged into your workflow.
