OSS advisories

OSV and GitHub advisory rows for named packages

This Actor queries OSV (and related GitHub security advisory metadata) for packages you list, with ecosystem and minSeverity filters, and emits vulnerability rows. Paste package names; it is not a license auditor.

Not a pentest. Not license-policy compliance. Not a substitute for your own patched-version verification. Informational CVE/advisory metadata only.

from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

Open OSS Vulnerability Monitor on Apify

OSS Vulnerability Monitor, not a neighboring Actor

Use this page for this Actor’s job. Use npm License & Deprecation Checker for npm license/deprecation; Use PyPI Vulnerability Scraper for PyPI + OSV package alerts; Use Security Headers Checker for HTTP header grades.

This Actornpm License & Deprecation CheckerPyPI Vulnerability ScraperSecurity Headers Checker
Intent OSS Vulnerability Monitornpm license/deprecationPyPI + OSV package alertsHTTP header grades
Primary input see schemapackagespackagesurls
What it reads Public sources listed on the Store pageregistry.npmjs.orgPyPI + OSVHTTP response headers
Primary output Dataset rows billed per live PPEnpm package rowsPyPI package rowsheader rows
Not this job Not a pentest. Not license-policy compliance. Not a substitute for your own patched-version verification. Informational CVE/advisory metadata only.Not OSV vulnerability matchingNot npm registry metadataNot OSV/CVE package vulns

Store ID: taroyamada/oss-vulnerability-monitor. Respect source terms, robots.txt, and rate limits.

Use cases

How is OSS Vulnerability Monitor different from npm License & Deprecation Checker and PyPI Vulnerability Scraper?

OSS Vulnerability Monitor (taroyamada/oss-vulnerability-monitor): This Actor queries OSV (and related GitHub security advisory metadata) for packages you list, with ecosystem and minSeverity filters, and emits vulnerability rows. Paste package names; it is not a license auditor. Not a pentest. Not license-policy compliance. Not a substitute for your own patched-version verification. Informational CVE/advisory metadata only. npm License & Deprecation Checker is for npm license/deprecation (input packages; registry.npmjs.org; npm package rows). Not OSV vulnerability matching. PyPI Vulnerability Scraper is for PyPI + OSV package alerts (input packages; PyPI + OSV; PyPI package rows). Not npm registry metadata. Security Headers Checker is for HTTP header grades (input urls; HTTP response headers; header rows). Not OSV/CVE package vulns.

What input is required?

Live required fields: packages. Published exampleRunInput is shown below. Configure packages to scan for known security vulnerabilities using OSV and GitHub Security Advisories.

Field Type Default Notes
packages any[] required empty required Packages. Packages to scan. Each entry is either a plain string (package name, defaults to ecosystem below) or an object with {name, ecosystem, version?}. Max 200.
ecosystem string npm Default Ecosystem. Ecosystem used for plain-string package names. OSV-supported values: npm, PyPI, Go, Maven, NuGet, Cargo, RubyGems, Packagist, Hex, crates.io, Android, OSS-Fuzz.
minSeverity string enum ALL Minimum Severity. Only include vulnerabilities at or above this severity level. CRITICAL > HIGH > MEDIUM > LOW. enum: ALL, LOW, MEDIUM, HIGH, CRITICAL
maxVulnsPerPackage integer 20 Max Vulnerabilities Per Package. Cap the number of individual vulnerability records returned per package (0 = unlimited). min=0 max=200
concurrency integer 5 Concurrency. Number of parallel OSV API requests min=1 max=10
timeoutMs integer 15000 Timeout (ms). Per-request timeout in milliseconds min=1000 max=30000
delivery string enum dataset Delivery. Where to send results: Apify dataset or webhook enum: dataset, webhook
webhookUrl string empty Webhook URL. Webhook URL to POST results to (if delivery=webhook)
dryRun boolean false Dry Run. Run without saving results (for testing)

Published Store example run input (omitted fields take schema defaults):

{
  "packages": [
    "lodash",
    "axios",
    "express"
  ],
  "ecosystem": "npm",
  "minSeverity": "ALL",
  "maxVulnsPerPackage": 10,
  "concurrency": 3,
  "delivery": "dataset",
  "dryRun": false
}

Run OSS Vulnerability Monitor on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

What does a result contain?

Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.

How is OSS Vulnerability Monitor priced?

Billing is pay per event. The live Store card is from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:

Event Price Emitted when
apify-default-dataset-item (result) $0.009 Single result in the default dataset.
apify-actor-start (Actor Start) $0.001 Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event).

The published README Cost block is stale versus the live Store pricing tab. README Cost quotes actor-start $0.01; live Actor Start is $0.001. README Cost quotes dataset-item $0.003; live primary is $0.009 (result). Live: result $0.009, Actor Start $0.001. This page quotes live PPE only.

from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

See OSS Vulnerability Monitor pricing on Apify

Limits to keep in mind

Open OSS Vulnerability Monitor on Apify

Related pages