OSV Open Source Vulnerabilities Scraper
Pricing
from $22.87 / 1,000 results
OSV Open Source Vulnerabilities Scraper
Query the OSV.dev open-source vulnerabilities database. Search by package (PyPI/npm/Go/Maven/RubyGems/crates.io/NuGet/Packagist), commit hash, or fetch a specific vulnerability by ID. Returns affected ranges, CVE aliases, severity, and references.
Pricing
from $22.87 / 1,000 results
Rating
0.0
(0)
Developer
ParseForge
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
0
Monthly active users
6 days ago
Last modified
Categories
Share

๐ฆ OSV Vulnerabilities Scraper
๐ Export open source vulnerability data in seconds. Pull advisories from the OSV.dev catalogue covering 30+ ecosystems including PyPI, npm, Go, Maven, RubyGems, crates.io, NuGet, Packagist, and major Linux distributions. No sign-up, no token, no manual pagination.
The OSV Vulnerabilities Scraper pulls open source vulnerability records from the OSV.dev community catalogue and returns 16 normalised fields per record, including affected package ranges, severity scores, cross-database aliases (GHSA, CVE, PYSEC, RUSTSEC, GO, OSV-xxxx), patched version events, references, and credits. The underlying catalogue is the de facto open source vulnerability database, aggregating data from GitHub, PyPA, RustSec, Go vulnerability database, OSS-Fuzz, and dozens of distro security teams.
The catalogue covers 30+ package ecosystems from language registries (PyPI, npm, Go, Maven, RubyGems, crates.io, NuGet, Packagist, Hex, Pub, Hackage) to operating system distributions (Debian, Ubuntu, Alpine, Rocky, AlmaLinux, SUSE, openSUSE, Wolfi, Chainguard) plus Bioconductor and CRAN for R. This Actor makes that data downloadable as CSV, Excel, JSON, or XML in minutes. Filters apply at the source, so you skip pagination, deduplication, and ecosystem-specific quirks entirely.
| ๐ฏ Target Audience | ๐ก Primary Use Cases |
|---|---|
| DevSecOps teams, SBOM tool builders, open source maintainers, package registry operators, supply-chain security vendors, container security teams | Dependency scanning, SBOM enrichment, package risk reports, ecosystem trend analysis, cross-database aliasing, container vulnerability triage |
๐ What the OSV Vulnerabilities Scraper does
Three workflows in a single Actor:
- ๐ฆ Package query. Look up every advisory affecting a package, optionally pinned to a version (e.g.
requestson PyPI,lodashon npm,log4j-coreon Maven). - ๐ Commit query. Search by Git commit SHA to surface vulnerabilities introduced in a specific revision.
- ๐ Vulnerability ID lookup. Fetch a single record or a batch of records by their identifier (GHSA-xxxx, CVE-xxxx, PYSEC-xxxx, RUSTSEC-xxxx, GO-xxxx, OSV-xxxx).
Each record includes the OSV ID, summary and full details, all known cross-database aliases, affected package list with version ranges and PURLs, severity entries with CVSS vectors, references, and credits.
๐ก Why it matters: SBOMs are only useful when paired with a fresh vulnerability feed. Building your own ingestion means handling 30+ ecosystem schemas, alias deduplication, version-range parsing, and the OSV pagination model. This Actor skips all of that and gives you a clean, downloadable dataset.
๐ Data fields
Each record includes: affected, aliases, details, id, maxSeverityScore, modified, published, purls, references, related, schema_version, scrapedAt, severity, summary, url. All 15 field names come from a real production run, so what you see here is what lands in your dataset.
๐ How to use
- ๐ Sign up. Create a free account with $5 credit (takes 2 minutes).
- ๐ Open the Actor. Go to the OSV Vulnerabilities Scraper page on the Apify Store.
- ๐ฏ Set input. Pick a mode, enter a package + ecosystem, a commit SHA, or a vulnerability ID, then set
maxItems. - ๐ Run it. Click Start and let the Actor collect your data.
- ๐ฅ Download. Grab your results in the Dataset tab as CSV, Excel, JSON, or XML.
โฑ๏ธ Total time from signup to downloaded dataset: 3-5 minutes. No coding required.
๐ Recommended Actors
- ๐ก๏ธ NIST NVD CVE Scraper - Official NVD catalogue with CVSS v4/v3/v2 scores
- ๐จ CISA KEV Scraper - Known Exploited Vulnerabilities catalogue with due dates
- ๐ EPSS Exploit Prediction Scraper - 30-day exploitation probability scores
- ๐ GitHub Security Advisories Scraper - GHSA + CVE advisories with patched versions
- ๐ฌ CIRCL CVE Scraper - CIRCL Luxembourg CVE catalogue with CWE and CAPEC
๐ก Pro Tip: browse the complete ParseForge collection for more security and reference-data scrapers.
โ ๏ธ Disclaimer: this Actor is an independent tool and is not affiliated with, endorsed by, or sponsored by OSV.dev, Google, or any of the upstream feed maintainers. All trademarks mentioned are the property of their respective owners. Only publicly available open source vulnerability data is collected.
๐ Need Help?
If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.
For faster answers, join our Discord. It's the best place to get support and suggest new actors.