OSV Scraper β Open Source Vulnerabilities for npm, PyPI & Go
Pricing
from $0.50 / 1,000 results
OSV Scraper β Open Source Vulnerabilities for npm, PyPI & Go
$0.5/1K π₯ Fast OSV vulnerability scraper! Package vulns across npm, PyPI, Go, Maven, crates, RubyGems & more β severity, aliases & fixed versions. JSON, CSV, Excel or API in seconds. Scan dependencies & pull thousands of advisories β‘
Pricing
from $0.50 / 1,000 results
Rating
0.0
(0)
Developer
ninhothedev
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
3 days ago
Last modified
Categories
Share
OSV Open Source Vulnerabilities Scraper
Get clean open-source vulnerability data for any package across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Hex & Pub: CVE/GHSA aliases, CVSS severity, affected versions and references. Powered by OSV.dev. As JSON, CSV or Excel. Free, no key, no proxy.
π΅ Pricing
Pay per result β ~$1 per 1,000 items. No subscription, no proxy needed. You only pay for the data you scrape, and new Apify accounts include free monthly credits so you can test it for $0.
π What can it extract?
- Vulnerability id (OSV/GHSA) and CVE/GHSA aliases
- Summary and full details
- CVSS severity vector or label (CRITICAL/HIGH/MODERATE/LOW)
- Affected versions (explicit versions + introduced/fixed ranges)
- Package name and ecosystem
- Published / modified dates and reference URLs
- Direct link to
osv.dev/vulnerability/{id}
π How do I use it?
- Click Try for free.
- Choose a mode: packages (scan package names in an ecosystem) or ids (fetch specific CVE/GHSA/OSV ids).
- Click Start and download results as JSON, CSV or Excel β or pull them via the API / schedule them.
βοΈ Input example
{"mode": "packages","ecosystem": "npm","packageNames": ["lodash", "django"],"maxItems": 100}
By id:
{"mode": "ids","vulnIds": ["GHSA-29mw-wpgm-hmr9"]}
π¦ Output example
{"id": "GHSA-29mw-wpgm-hmr9","aliases": ["CVE-2020-28500"],"package": "lodash","ecosystem": "npm","severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","affected_versions": ["introduced: 4.0.0", "fixed: 4.17.21"],"url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"}
π― Use cases
- Dependency scanning β flag vulnerable packages in your lockfiles
- Security β monitor advisories for the libraries you ship
- SBOM β enrich software bills of materials with known CVEs
- Compliance β evidence for audits and vulnerability reporting
π° How much will it cost?
You pay only the per-result price (no proxy cost): 100 β ~$0.10 Β· 1,000 β ~$1 Β· 10,000 β ~$10
π Why this one
| Feature | This actor | Others |
|---|---|---|
| 10+ ecosystems (npm/PyPI/Go/Mavenβ¦) | β | often one |
| CVE + GHSA aliases | β | partial |
| Affected version ranges | β | rarely |
| No key needed | β | sometimes |
π Related actors
- NVD CVE Scraper β NIST CVE feed
- npm Package Scraper β npm metadata
- PyPI Scraper β Python packages
- crates.io Scraper β Rust crates
β FAQ
Key/proxy? No β OSV.dev is a free public API. Which ecosystems? npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Hex, Pub. How do I look up a specific CVE? Use mode ids with the CVE/GHSA/OSV identifier.
π Support
Found a bug or need an extra field? Open an issue on the actor β fixes and new fields ship fast.
Legal & privacy
Data via the OSV.dev public API (open-source vulnerability database).
Keywords: osv scraper, vulnerability scanner, cve scraper, ghsa, dependency scanning, sbom, security, npm pypi go maven, cvss, JSON CSV Excel