PyPI security
PyPI package metadata, releases, downloads, and OSV alerts
This Actor looks up PyPI projects you name and can attach release history, download stats, and OSV vulnerability summaries. Python/PyPI only — not npm.
Not npm. Not a substitute for pinning and reviewing advisories yourself. Informational package metadata only.
from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
Open PyPI Vulnerability Scraper on Apify
PyPI Vulnerability Scraper, not a neighboring Actor
Use this page for this Actor’s job. Use OSS Vulnerability Monitor for OSV/GitHub advisories; Use npm License & Deprecation Checker for npm license/deprecation; Use PyPI Package & Dependency Scraper for PyPI deps/releases.
| This Actor | OSS Vulnerability Monitor | npm License & Deprecation Checker | PyPI Package & Dependency Scraper | |
|---|---|---|---|---|
| Intent | PyPI Vulnerability Scraper | OSV/GitHub advisories | npm license/deprecation | PyPI deps/releases |
| Primary input | see schema | packages | packages | packages |
| What it reads | Public sources listed on the Store page | OSV + GitHub Advisories | registry.npmjs.org | PyPI JSON + OSV |
| Primary output | Dataset rows billed per live PPE | vuln rows | npm package rows | PyPI dep rows |
| Not this job | Not npm. Not a substitute for pinning and reviewing advisories yourself. Informational package metadata only. | Not license-policy trees | Not OSV vulnerability matching | Not npm trees |
Store ID: taroyamada/pypi-package-intelligence. Respect source terms, robots.txt, and rate limits.
Use cases
- Named-package PyPI watches
- OSV flags via includeVulnerabilities
- Release-history extracts
How is PyPI Vulnerability Scraper different from OSS Vulnerability Monitor and npm License & Deprecation Checker?
PyPI Vulnerability Scraper (taroyamada/pypi-package-intelligence): This Actor looks up PyPI projects you name and can attach release history, download stats, and OSV vulnerability summaries. Python/PyPI only — not npm. Not npm. Not a substitute for pinning and reviewing advisories yourself. Informational package metadata only. OSS Vulnerability Monitor is for OSV/GitHub advisories (input packages; OSV + GitHub Advisories; vuln rows). Not license-policy trees. npm License & Deprecation Checker is for npm license/deprecation (input packages; registry.npmjs.org; npm package rows). Not OSV vulnerability matching. PyPI Package & Dependency Scraper is for PyPI deps/releases (input packages; PyPI JSON + OSV; PyPI dep rows). Not npm trees.
What input is required?
Live required fields: packages. Published exampleRunInput is shown below. PyPI package names (e.g
| Field | Type | Default | Notes |
|---|---|---|---|
packages |
any[] required | empty |
required Package Names. PyPI package names to fetch (e.g. 'requests', 'numpy'). Names are normalised to lowercase per PEP 503. Max 100 per run. |
includeReleaseHistory |
boolean | true |
Include Release History. When true, includes the full release history (all version upload dates) in the output. |
includeDownloadStats |
boolean | false |
Include Download Stats (pypistats.org). When true, fetches recent download counts from pypistats.org (a third-party service). Emits a warning when unavailable. |
includeVulnerabilities |
boolean | false |
Include OSV Vulnerability Summary. When true, queries the OSV API (api.osv.dev) for known vulnerability advisories for each package. Off by default — treat results as advisory summaries only. |
concurrency |
integer | 5 |
Concurrency. Number of packages to fetch in parallel. Default 5. min=1 max=10 |
timeoutMs |
integer | 15000 |
Request Timeout (ms). Per-request timeout in milliseconds. min=1000 max=30000 |
delivery |
string enum | dataset |
Delivery. Where to send results: dataset or webhook. enum: dataset, webhook |
webhookUrl |
string | empty |
Webhook URL. Webhook URL to POST results to when delivery=webhook. |
dryRun |
boolean | false |
Dry Run. Run without saving results to the dataset. |
Published Store example run input (omitted fields take schema defaults):
{
"packages": [
"requests",
"numpy"
],
"includeReleaseHistory": true,
"includeDownloadStats": false,
"includeVulnerabilities": false,
"concurrency": 5,
"timeoutMs": 15000,
"delivery": "dataset",
"dryRun": false
}
Run PyPI Vulnerability Scraper on Apify
How do dataset, webhook, and dry-run delivery work?
delivery defaults to dataset on the live schema. Dataset output is the billable surface when rows are written. webhookUrl is used when delivery is webhook (and typically not during dryRun). dryRun true validates or samples without the usual dataset/webhook side effects described on the Store schema. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
What does a result contain?
Published README Output Example / Sample Output JSON. Treat README samples as illustrations, not a live coverage guarantee. There is no published output JSON schema on the Store page.
How is PyPI Vulnerability Scraper priced?
Billing is pay per event. The live Store card is from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE. Current PPE:
| Event | Price | Emitted when |
|---|---|---|
apify-default-dataset-item (result) |
$0.008 | Single result in the default dataset. |
apify-actor-start (Actor Start) |
$0.001 | Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event). |
from $8.00 / 1,000 result ($0.008 per delivered apify-default-dataset-item). $0.001 Actor Start. Unchanged runs that write zero default-dataset rows typically charge $0.00 on current PPE.
See PyPI Vulnerability Scraper pricing on Apify
Limits to keep in mind
- packages required
- PyPI + OSV public APIs
- concurrency / timeoutMs caps
- Not npm
- Respect source terms, robots.txt, and rate limits.
Open PyPI Vulnerability Scraper on Apify
Related pages
- OSS Vulnerability Monitor — Cross-ecosystem OSV; this page is PyPI-first.
- npm License & Deprecation Checker — npm, not PyPI.
- PyPI Package & Dependency Scraper — Declared deps/releases in more rows.
- PyPI & npm Dependency Risk Report — npm+PyPI upgrade alerts.
- Tools