PyPI security

PyPI package metadata, releases, downloads, and OSV alerts

This Actor looks up PyPI projects you name and can attach release history, download stats, and OSV vulnerability summaries. Python/PyPI only — not npm.

Not npm. Not a substitute for pinning and reviewing advisories yourself. Informational package metadata only.

from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

Open PyPI Vulnerability Scraper on Apify

PyPI Vulnerability Scraper, not a neighboring Actor

Use this page for this Actor’s job. Use OSS Vulnerability Monitor for OSV/GitHub advisories; Use npm License & Deprecation Checker for npm license/deprecation; Use PyPI Package & Dependency Scraper for PyPI deps/releases.

This ActorOSS Vulnerability Monitornpm License & Deprecation CheckerPyPI Package & Dependency Scraper
Intent PyPI Vulnerability ScraperOSV/GitHub advisoriesnpm license/deprecationPyPI deps/releases
Primary input see schemapackagespackagespackages
What it reads Public sources listed on the Store pageOSV + GitHub Advisoriesregistry.npmjs.orgPyPI JSON + OSV
Primary output Dataset rows billed per live PPEvuln rowsnpm package rowsPyPI dep rows
Not this job Not npm. Not a substitute for pinning and reviewing advisories yourself. Informational package metadata only.Not license-policy treesNot OSV vulnerability matchingNot npm trees

Store ID: taroyamada/pypi-package-intelligence. Respect source terms, robots.txt, and rate limits.

Use cases

How is PyPI Vulnerability Scraper different from OSS Vulnerability Monitor and npm License & Deprecation Checker?

PyPI Vulnerability Scraper (taroyamada/pypi-package-intelligence): This Actor looks up PyPI projects you name and can attach release history, download stats, and OSV vulnerability summaries. Python/PyPI only — not npm. Not npm. Not a substitute for pinning and reviewing advisories yourself. Informational package metadata only. OSS Vulnerability Monitor is for OSV/GitHub advisories (input packages; OSV + GitHub Advisories; vuln rows). Not license-policy trees. npm License & Deprecation Checker is for npm license/deprecation (input packages; registry.npmjs.org; npm package rows). Not OSV vulnerability matching. PyPI Package & Dependency Scraper is for PyPI deps/releases (input packages; PyPI JSON + OSV; PyPI dep rows). Not npm trees.

What input is required?

Live required fields: packages. Published exampleRunInput is shown below. PyPI package names (e.g

Field Type Default Notes
packages any[] required empty required Package Names. PyPI package names to fetch (e.g. 'requests', 'numpy'). Names are normalised to lowercase per PEP 503. Max 100 per run.
includeReleaseHistory boolean true Include Release History. When true, includes the full release history (all version upload dates) in the output.
includeDownloadStats boolean false Include Download Stats (pypistats.org). When true, fetches recent download counts from pypistats.org (a third-party service). Emits a warning when unavailable.
includeVulnerabilities boolean false Include OSV Vulnerability Summary. When true, queries the OSV API (api.osv.dev) for known vulnerability advisories for each package. Off by default — treat results as advisory summaries only.
concurrency integer 5 Concurrency. Number of packages to fetch in parallel. Default 5. min=1 max=10
timeoutMs integer 15000 Request Timeout (ms). Per-request timeout in milliseconds. min=1000 max=30000
delivery string enum dataset Delivery. Where to send results: dataset or webhook. enum: dataset, webhook
webhookUrl string empty Webhook URL. Webhook URL to POST results to when delivery=webhook.
dryRun boolean false Dry Run. Run without saving results to the dataset.

Published Store example run input (omitted fields take schema defaults):

{
  "packages": [
    "requests",
    "numpy"
  ],
  "includeReleaseHistory": true,
  "includeDownloadStats": false,
  "includeVulnerabilities": false,
  "concurrency": 5,
  "timeoutMs": 15000,
  "delivery": "dataset",
  "dryRun": false
}

Run PyPI Vulnerability Scraper on Apify

How do dataset, webhook, and dry-run delivery work?

delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

What does a result contain?

Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.

How is PyPI Vulnerability Scraper priced?

Billing is pay per event. The live Store card is from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:

Event Price Emitted when
apify-default-dataset-item (result) $0.008 Single result in the default dataset.
apify-actor-start (Actor Start) $0.001 Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event).

from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.

See PyPI Vulnerability Scraper pricing on Apify

Limits to keep in mind

Open PyPI Vulnerability Scraper on Apify

Related pages