OSS advisories
OSV and GitHub advisory rows for named packages
This Actor queries OSV (and related GitHub security advisory metadata) for packages you list, with ecosystem and minSeverity filters, and emits vulnerability rows. Paste package names; it is not a license auditor.
Not a pentest. Not license-policy compliance. Not a substitute for your own patched-version verification. Informational CVE/advisory metadata only.
from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
Open OSS Vulnerability Monitor on Apify
OSS Vulnerability Monitor, not a neighboring Actor
Use this page for this Actor’s job. Use npm License & Deprecation Checker for npm license/deprecation; Use PyPI Vulnerability Scraper for PyPI + OSV package alerts; Use Security Headers Checker for HTTP header grades.
| This Actor | npm License & Deprecation Checker | PyPI Vulnerability Scraper | Security Headers Checker | |
|---|---|---|---|---|
| Intent | OSS Vulnerability Monitor | npm license/deprecation | PyPI + OSV package alerts | HTTP header grades |
| Primary input | see schema | packages | packages | urls |
| What it reads | Public sources listed on the Store page | registry.npmjs.org | PyPI + OSV | HTTP response headers |
| Primary output | Dataset rows billed per live PPE | npm package rows | PyPI package rows | header rows |
| Not this job | Not a pentest. Not license-policy compliance. Not a substitute for your own patched-version verification. Informational CVE/advisory metadata only. | Not OSV vulnerability matching | Not npm registry metadata | Not OSV/CVE package vulns |
Store ID: taroyamada/oss-vulnerability-monitor. Respect source terms, robots.txt, and rate limits.
Use cases
- Pinned package CVE watches
- minSeverity filters
- Scheduled ecosystem scans
How is OSS Vulnerability Monitor different from npm License & Deprecation Checker and PyPI Vulnerability Scraper?
OSS Vulnerability Monitor (taroyamada/oss-vulnerability-monitor): This Actor queries OSV (and related GitHub security advisory metadata) for packages you list, with ecosystem and minSeverity filters, and emits vulnerability rows. Paste package names; it is not a license auditor. Not a pentest. Not license-policy compliance. Not a substitute for your own patched-version verification. Informational CVE/advisory metadata only. npm License & Deprecation Checker is for npm license/deprecation (input packages; registry.npmjs.org; npm package rows). Not OSV vulnerability matching. PyPI Vulnerability Scraper is for PyPI + OSV package alerts (input packages; PyPI + OSV; PyPI package rows). Not npm registry metadata. Security Headers Checker is for HTTP header grades (input urls; HTTP response headers; header rows). Not OSV/CVE package vulns.
What input is required?
Live required fields: packages. Published exampleRunInput is shown below. Configure packages to scan for known security vulnerabilities using OSV and GitHub Security Advisories.
| Field | Type | Default | Notes |
|---|---|---|---|
packages |
any[] required | empty |
required Packages. Packages to scan. Each entry is either a plain string (package name, defaults to ecosystem below) or an object with {name, ecosystem, version?}. Max 200. |
ecosystem |
string | npm |
Default Ecosystem. Ecosystem used for plain-string package names. OSV-supported values: npm, PyPI, Go, Maven, NuGet, Cargo, RubyGems, Packagist, Hex, crates.io, Android, OSS-Fuzz. |
minSeverity |
string enum | ALL |
Minimum Severity. Only include vulnerabilities at or above this severity level. CRITICAL > HIGH > MEDIUM > LOW. enum: ALL, LOW, MEDIUM, HIGH, CRITICAL |
maxVulnsPerPackage |
integer | 20 |
Max Vulnerabilities Per Package. Cap the number of individual vulnerability records returned per package (0 = unlimited). min=0 max=200 |
concurrency |
integer | 5 |
Concurrency. Number of parallel OSV API requests min=1 max=10 |
timeoutMs |
integer | 15000 |
Timeout (ms). Per-request timeout in milliseconds min=1000 max=30000 |
delivery |
string enum | dataset |
Delivery. Where to send results: Apify dataset or webhook enum: dataset, webhook |
webhookUrl |
string | empty |
Webhook URL. Webhook URL to POST results to (if delivery=webhook) |
dryRun |
boolean | false |
Dry Run. Run without saving results (for testing) |
Published Store example run input (omitted fields take schema defaults):
{
"packages": [
"lodash",
"axios",
"express"
],
"ecosystem": "npm",
"minSeverity": "ALL",
"maxVulnsPerPackage": 10,
"concurrency": 3,
"delivery": "dataset",
"dryRun": false
}
Run OSS Vulnerability Monitor on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
What does a result contain?
Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.
How is OSS Vulnerability Monitor priced?
Billing is pay per event. The live Store card is from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:
| Event | Price | Emitted when |
|---|---|---|
apify-default-dataset-item (result) |
$0.009 | Single result in the default dataset. |
apify-actor-start (Actor Start) |
$0.001 | Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event). |
The published README Cost block is stale versus the live Store pricing tab. README Cost quotes actor-start $0.01; live Actor Start is $0.001. README Cost quotes dataset-item $0.003; live primary is $0.009 (result). Live: result $0.009, Actor Start $0.001. This page quotes live PPE only.
from $9.00 / 1,000 result ($0.009 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
See OSS Vulnerability Monitor pricing on Apify
Limits to keep in mind
- packages required
- OSV/GitHub public APIs
- maxVulnsPerPackage cap
- Not a pentest
- Respect source terms, robots.txt, and rate limits.
Open OSS Vulnerability Monitor on Apify
Related pages
- npm License & Deprecation Checker — License/deprecation, not CVEs.
- PyPI Vulnerability Scraper — PyPI-focused package + OSV rows.
- Security Headers Checker — HTTP headers, not package CVEs.
- PyPI & npm Dependency Risk Report — pinned package upgrade risk.
- CISA KEV Asset Remediation Report — inventory vs official CISA KEV, not OSV package rows.
- Tools