Endpoint · evidenceGET2s.io /api/security/package ?ecosystem=npm&name=lodash&version=4.17.20
Security and provenance for an open-source package, composed live from three authoritative sources in one call.
Read more
Security and provenance for an open-source package, composed live from three authoritative sources in one call. Pass ecosystem (npm, pypi, go, maven, cargo, nuget) + name (+ optional version; defaults to latest). Returns: known vulnerabilities from OSV (osv.dev — aggregates GitHub Security Advisories, PyPA, RustSec, Go vuln DB, etc.) each with its id, CVE aliases, summary, severity, and references; the resolved license and deprecation status (deps.dev); and the source repo's OpenSSF Scorecard health score (overall + per-check) plus stars/forks/open-issues. All live — newly-disclosed advisories appear within hours. Distinct from registry.npm-lookup / pypi-lookup (metadata only): this answers "is this dependency safe to add, what license does it carry, and how well-maintained is it."Overview
Grade?
UNRATED
0 of 30 paid calls toward a letter
Price
$0.0054 per call
Paid calls
none yet
delivery unknown until someone pays
More info
Seller?
URL
https://2s.io/api/security/package?ecosystem=npm&name=lodash&version=4.17.20
Seen
first 29 days ago · last 9 hr ago
54 free handshakes
Payment
Pays through
x402
Offered on?
Base USDC, Solana
Listed on?
Base, Solana
Buy it through Teppi
- ?Pay on delivery
- 0.007400 USDC (0.005400 to the seller, 0.002000 fee)
- Where
- https://api.teppi.xyz/v1/via/cap_01M1RDABB2M8VA3C4581JNSBB1
- ?Ask the price
curl -si https://api.teppi.xyz/v1/via/cap_01M1RDABB2M8VA3C4581JNSBB1
About
- ?Description
- Security and provenance for an open-source package, composed live from three authoritative sources in one call. Pass ecosystem (npm, pypi, go, maven, cargo, nuget) + name (+ optional version; defaults to latest). Returns: known vulnerabilities from OSV (osv.dev — aggregates GitHub Security Advisories, PyPA, RustSec, Go vuln DB, etc.) each with its id, CVE aliases, summary, severity, and references; the resolved license and deprecation status (deps.dev); and the source repo's OpenSSF Scorecard health score (overall + per-check) plus stars/forks/open-issues. All live — newly-disclosed advisories appear within hours. Distinct from registry.npm-lookup / pypi-lookup (metadata only): this answers "is this dependency safe to add, what license does it carry, and how well-maintained is it."
- URL
- https://2s.io/api/security/package?ecosystem=npm&name=lodash&version=4.17.20
- Method
- GET
- Class
- evidence
- ?Checkable to
- L1
- Endpoint id
- cap_01M1RDABB2M8VA3C4581JNSBB1
- ?Badge
Reads live. UNRATED until paid calls earn a letter.
- Markdown
- [](https://teppi.xyz/endpoint/cap_01M1RDABB2M8VA3C4581JNSBB1)
- HTML
- <a href="https://teppi.xyz/endpoint/cap_01M1RDABB2M8VA3C4581JNSBB1"><img src="https://api.teppi.xyz/badge/cap_01M1RDABB2M8VA3C4581JNSBB1.svg" alt="Teppi delivery record"></a>
- Image
- https://api.teppi.xyz/badge/cap_01M1RDABB2M8VA3C4581JNSBB1.svg
Verify it yourself
npx teppi-check https://2s.io/api/security/package?ecosystem=npm&name=lodash&version=4.17.20curl -s https://api.teppi.xyz/v1/trust/cap_01M1RDABB2M8VA3C4581JNSBB1