Server definition
- Hash
- sha256:159a7a00df5d92f4c7ea724fc6de5e164f221c691729115625b34349852fbb60
- What it is
- What a remote MCP server returned when asked what it offers: 4 tools
The blob, as servednamed by its sha256
{
"instructions": "This server provides read-only access to the OSV.dev vulnerability database.\n- Use osv_list_ecosystems to discover valid ecosystem identifier strings before querying.\n- Use osv_query_package to check if a single package version is vulnerable.\n- Use osv_query_batch for dependency audits — pass a full lockfile as {name, ecosystem, version} tuples.\n- Use osv_get_vulnerability for the full advisory record when osv_query_package returns a vuln ID.\n- OSV results include aliases (CVE IDs) — chain these to nist-nvd-mcp-server for CVSS scoring, EPSS, and CISA KEV status.\n- No API key required. No rate limit published — prefer batch queries over repeated single queries.",
"tools": [
{
"description": "Fetch the full advisory record for an OSV vulnerability ID. Returns the complete record: summary, full details text, CVE aliases, all affected packages and version ranges, fix versions, CVSS severity vectors, CWE weakness IDs, and references. Use when osv_query_package or osv_query_batch returns a vuln ID and you need the full advisory context — eligibility criteria, scope of affected packages, or remediation guidance.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"id": {
"description": "One exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include \"GHSA-\" (GitHub), \"PYSEC-\" (PyPI), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"USN-\" (Ubuntu), \"RHSA-\" (Red Hat), and \"CVE-\". No wildcards or partial IDs — take IDs from osv_query_package or osv_query_batch results. Example: \"GHSA-29mw-wpgm-hmr9\".",
"pattern": "^[A-Za-z][A-Za-z0-9_]*-\\S(.*\\S)?$",
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
},
"name": "osv_get_vulnerability",
"outputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"anyOf": [
{
"not": {
"required": [
"error"
]
},
"required": [
"id",
"summary",
"details",
"aliases",
"published",
"modified",
"severity",
"severityLabel",
"severitySource",
"affected",
"cweIds",
"references",
"schemaVersion"
]
},
{
"required": [
"error"
]
}
],
"properties": {
"affected": {
"description": "All affected packages and their version ranges. An advisory may span multiple packages or ecosystems.",
"items": {
"additionalProperties": false,
"description": "One affected package entry.",
"properties": {
"ecosystem": {
"description": "Affected package ecosystem. Empty for source-only advisories.",
"type": "string"
},
"packageName": {
"description": "Affected package name. Empty for source-only advisories (GIT ranges with no package identity).",
"type": "string"
},
"purl": {
"description": "Package URL (e.g. \"pkg:npm/lodash\").",
"type": "string"
},
"ranges": {
"description": "Version ranges affected.",
"items": {
"additionalProperties": false,
"description": "One version range.",
"properties": {
"events": {
"description": "Ordered event boundaries defining the affected interval(s) — the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.",
"items": {
"additionalProperties": false,
"description": "One ordered range event.",
"properties": {
"type": {
"description": "Event boundary type: \"introduced\", \"fixed\", \"last_affected\", or \"limit\".",
"type": "string"
},
"value": {
"description": "Version string or commit identifier at this boundary.",
"type": "string"
}
},
"required": [
"type",
"value"
],
"type": "object"
},
"type": "array"
},
"fixed": {
"description": "The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[]).",
"type": "string"
},
"introduced": {
"description": "First affected version (convenience view — the last \"introduced\" event; see events[] for full interval order).",
"type": "string"
},
"lastAffected": {
"description": "Last affected version when no fix exists (convenience view — see events[]).",
"type": "string"
},
"rangeType": {
"description": "\"SEMVER\", \"ECOSYSTEM\", or \"GIT\".",
"type": "string"
},
"repo": {
"description": "Source repository URL for GIT ranges. Absent on version ranges.",
"type": "string"
}
},
"required": [
"rangeType"
],
"type": "object"
},
"type": "array"
},
"severity": {
"description": "Severity entries scoped to this package. Present only when the advisory scores packages separately; the record-level severity is then empty.",
"items": {
"additionalProperties": false,
"description": "One package-level severity entry.",
"properties": {
"score": {
"description": "CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\".",
"type": "string"
},
"type": {
"description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\".",
"type": "string"
}
},
"required": [
"type",
"score"
],
"type": "object"
},
"type": "array"
},
"versions": {
"description": "Explicit affected versions enumerated by the advisory. Absent or empty when affected versions are expressed only as ranges.",
"items": {
"description": "An explicitly-listed affected version.",
"type": "string"
},
"type": "array"
}
},
"required": [
"packageName",
"ecosystem",
"ranges"
],
"type": "object"
},
"type": "array"
},
"aliases": {
"description": "Alternative IDs — usually CVE IDs. Accepted by nvd_get_cve on nist-nvd-mcp-server for CVSS base score, EPSS exploitation probability, and CISA KEV status.",
"items": {
"description": "An alternative ID (usually a CVE ID).",
"type": "string"
},
"type": "array"
},
"cweIds": {
"description": "CWE weakness classifications (e.g. [\"CWE-79\"]). Present on GitHub Advisory Database records; empty otherwise.",
"items": {
"description": "A CWE weakness ID.",
"type": "string"
},
"type": "array"
},
"details": {
"description": "Full advisory text, typically in Markdown. May include proof-of-concept, reproduction steps, or remediation guidance.",
"type": "string"
},
"error": {
"additionalProperties": {},
"description": "Present when the call failed. Absent on success.",
"properties": {
"code": {
"description": "JSON-RPC error code for this failure.",
"maximum": 9007199254740991,
"minimum": -9007199254740991,
"type": "integer"
},
"data": {
"additionalProperties": {},
"properties": {
"reason": {
"description": "Machine-readable failure mode. Declared by this tool: `vulnerability_not_found`: The requested OSV ID does not exist in the database. Other values are possible when a failure originates below the handler.",
"examples": [
"vulnerability_not_found"
],
"type": "string"
},
"recovery": {
"additionalProperties": {},
"description": "Actionable next step for the caller.",
"properties": {
"hint": {
"type": "string"
}
},
"required": [
"hint"
],
"type": "object"
},
"retryable": {
"description": "Whether retrying may succeed.",
"type": "boolean"
}
},
"type": "object"
},
"message": {
"description": "Human-readable description of what went wrong.",
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"id": {
"description": "OSV vulnerability ID.",
"type": "string"
},
"modified": {
"description": "ISO 8601 timestamp of last modification.",
"type": "string"
},
"published": {
"description": "ISO 8601 timestamp when published.",
"type": "string"
},
"references": {
"description": "Advisory references — NVD links, patches, vendor advisories, PoC reports.",
"items": {
"additionalProperties": false,
"description": "One reference entry.",
"properties": {
"type": {
"description": "Reference type: \"ADVISORY\", \"WEB\", \"PACKAGE\", \"REPORT\", \"FIX\", \"GIT\", etc.",
"type": "string"
},
"url": {
"description": "URL of the reference.",
"type": "string"
}
},
"required": [
"type",
"url"
],
"type": "object"
},
"type": "array"
},
"schemaVersion": {
"description": "OSV schema version this record conforms to (e.g. \"1.7.3\").",
"type": "string"
},
"severity": {
"description": "Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately.",
"items": {
"additionalProperties": false,
"description": "One record-level severity entry.",
"properties": {
"score": {
"description": "CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\".",
"type": "string"
},
"type": {
"description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\".",
"type": "string"
}
},
"required": [
"type",
"score"
],
"type": "object"
},
"type": "array"
},
"severityLabel": {
"description": "Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label.",
"type": [
"string",
"null"
]
},
"severitySource": {
"anyOf": [
{
"additionalProperties": false,
"properties": {
"computedScore": {
"description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
"type": "number"
},
"score": {
"description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.",
"type": "string"
},
"type": {
"description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.",
"enum": [
"database_specific",
"Ubuntu",
"CVSS_V3",
"CVSS_V4"
],
"type": "string"
}
},
"required": [
"type",
"score"
],
"type": "object"
},
{
"type": "null"
}
],
"description": "The severity entry severityLabel was derived from. Null exactly when the label is."
},
"summary": {
"description": "One-line advisory description.",
"type": "string"
},
"withdrawn": {
"description": "ISO 8601 timestamp when this advisory was withdrawn. Present ONLY on withdrawn advisories — a withdrawn record has been retracted and must not be treated as an active vulnerability.",
"type": "string"
}
},
"type": "object"
}
},
{
"description": "Return the supported ecosystem identifier strings for osv_query_package and osv_query_batch: every ecosystem the OSV schema names that OSV.dev accepts at query time, plus GIT, as verified on 2026-09-24. Ecosystem strings are case-sensitive exact matches — passing \"pypi\" instead of \"PyPI\" returns an error from the API. Use this tool to discover valid ecosystem strings before querying, or to verify an ecosystem identifier from a lockfile format. The list is static and may lag ecosystems added after that date.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "osv_list_ecosystems",
"outputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"anyOf": [
{
"not": {
"required": [
"error"
]
},
"required": [
"ecosystems",
"note"
]
},
{
"required": [
"error"
]
}
],
"properties": {
"ecosystems": {
"description": "Supported ecosystem identifier strings. These are case-sensitive exact matches required by the ecosystem parameter of osv_query_package and osv_query_batch.",
"items": {
"description": "A supported ecosystem identifier string.",
"type": "string"
},
"type": "array"
},
"error": {
"additionalProperties": {},
"description": "Present when the call failed. Absent on success.",
"properties": {
"code": {
"description": "JSON-RPC error code for this failure.",
"maximum": 9007199254740991,
"minimum": -9007199254740991,
"type": "integer"
},
"data": {
"additionalProperties": {},
"properties": {
"reason": {
"description": "Machine-readable failure mode.",
"type": "string"
},
"recovery": {
"additionalProperties": {},
"description": "Actionable next step for the caller.",
"properties": {
"hint": {
"type": "string"
}
},
"required": [
"hint"
],
"type": "object"
},
"retryable": {
"description": "Whether retrying may succeed.",
"type": "boolean"
}
},
"type": "object"
},
"message": {
"description": "Human-readable description of what went wrong.",
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"note": {
"description": "Advisory note about list currency and canonical source.",
"type": "string"
}
},
"type": "object"
}
},
{
"description": "Query vulnerabilities for multiple packages in one call — the primary tool for dependency audits, SBOM scanning, and lockfile triage. Pass an array of {name, ecosystem, version} tuples (up to 1000). Each entry in the response corresponds positionally to the input. Each finding includes CVE aliases for chaining to nist-nvd-mcp-server for CVSS scoring.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"packages": {
"description": "Packages to audit. One entry per dependency. Positional: result[i] corresponds to packages[i].",
"items": {
"description": "One package to audit.",
"properties": {
"ecosystem": {
"description": "Ecosystem identifier. Case-sensitive exact match. Use osv_list_ecosystems to validate.",
"pattern": "\\S",
"type": "string"
},
"name": {
"description": "Package name as it appears in the ecosystem.",
"pattern": "\\S",
"type": "string"
},
"version": {
"description": "Exact version string to check.",
"pattern": "\\S",
"type": "string"
}
},
"required": [
"name",
"ecosystem",
"version"
],
"type": "object"
},
"maxItems": 1000,
"minItems": 1,
"type": "array"
}
},
"required": [
"packages"
],
"type": "object"
},
"name": "osv_query_batch",
"outputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"anyOf": [
{
"not": {
"required": [
"error"
]
},
"required": [
"results",
"summary"
]
},
{
"required": [
"error"
]
}
],
"properties": {
"effectiveQuery": {
"description": "Compact scan summary (package and outcome counts), echoed on edge-case batches for content-only clients.",
"type": "string"
},
"error": {
"additionalProperties": {},
"description": "Present when the call failed. Absent on success.",
"properties": {
"code": {
"description": "JSON-RPC error code for this failure.",
"maximum": 9007199254740991,
"minimum": -9007199254740991,
"type": "integer"
},
"data": {
"additionalProperties": {},
"properties": {
"reason": {
"description": "Machine-readable failure mode.",
"type": "string"
},
"recovery": {
"additionalProperties": {},
"description": "Actionable next step for the caller.",
"properties": {
"hint": {
"type": "string"
}
},
"required": [
"hint"
],
"type": "object"
},
"retryable": {
"description": "Whether retrying may succeed.",
"type": "boolean"
}
},
"type": "object"
},
"message": {
"description": "Human-readable description of what went wrong.",
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"notice": {
"description": "Present on all-clean or all-errors batches — the aggregate outcome for content-only clients.",
"type": "string"
},
"results": {
"description": "Per-package results, positionally matching the input array.",
"items": {
"additionalProperties": false,
"description": "Result for one package.",
"properties": {
"ecosystem": {
"description": "Ecosystem from input.",
"type": "string"
},
"error": {
"description": "Per-package error message (e.g. invalid ecosystem). Null on success.",
"type": [
"string",
"null"
]
},
"name": {
"description": "Package name from input.",
"type": "string"
},
"truncated": {
"description": "True when OSV paginated beyond the fetch cap for this package — its result may be INCOMPLETE. A truncated row with no vulnerabilities is NOT confirmed clean.",
"type": "boolean"
},
"version": {
"description": "Version from input.",
"type": "string"
},
"vulnCount": {
"description": "Number of vulnerabilities found. 0 when not vulnerable or on error.",
"type": "number"
},
"vulnerable": {
"description": "True if any vulnerabilities were found.",
"type": "boolean"
},
"vulns": {
"description": "Vulnerabilities found. Empty array when clean.",
"items": {
"additionalProperties": false,
"description": "One vulnerability found for this package.",
"properties": {
"aliases": {
"description": "CVE IDs and other aliases. Accepted by nist-nvd-mcp-server for CVSS/KEV/EPSS context.",
"items": {
"description": "A CVE ID or other alias.",
"type": "string"
},
"type": "array"
},
"fixedVersions": {
"description": "Every fixed version the advisory lists for this row's package, in record order — one per affected interval, typically one per release line. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package.",
"items": {
"description": "A version that fixes the vulnerability for this package.",
"type": "string"
},
"type": "array"
},
"id": {
"description": "OSV vulnerability ID.",
"type": "string"
},
"severityLabel": {
"description": "Severity label: \"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\", or null. Same derivation as osv_query_package: database_specific.severity, then an Ubuntu priority, then the highest CVSS v3/v4 score, using this row's package-level severity entries when the record has none.",
"type": [
"string",
"null"
]
},
"summary": {
"description": "One-line advisory description.",
"type": "string"
}
},
"required": [
"id",
"summary",
"aliases",
"severityLabel",
"fixedVersions"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"name",
"ecosystem",
"version",
"vulnerable",
"truncated",
"error",
"vulnCount",
"vulns"
],
"type": "object"
},
"type": "array"
},
"summary": {
"additionalProperties": false,
"description": "Aggregate statistics across the full batch.",
"properties": {
"cleanCount": {
"description": "Packages confirmed clean — no vulnerabilities, no error, and not truncated.",
"type": "number"
},
"errorCount": {
"description": "Packages that returned an error (e.g. invalid ecosystem).",
"type": "number"
},
"totalPackages": {
"description": "Total packages queried.",
"type": "number"
},
"totalVulns": {
"description": "Total vulnerability instances across all packages (may double-count shared advisories).",
"type": "number"
},
"truncatedCount": {
"description": "Packages whose OSV results were truncated (may be incomplete). A truncated package with no findings is NOT counted as clean.",
"type": "number"
},
"vulnerableCount": {
"description": "Packages with at least one vulnerability.",
"type": "number"
},
"worstSeverity": {
"description": "Highest severity label seen across all findings, or null if no severity data available.",
"type": [
"string",
"null"
]
}
},
"required": [
"totalPackages",
"vulnerableCount",
"cleanCount",
"truncatedCount",
"errorCount",
"totalVulns",
"worstSeverity"
],
"type": "object"
}
},
"type": "object"
}
},
{
"description": "Query known vulnerabilities for a single package version across any supported ecosystem. Returns all matching OSV advisories with severity (CVSS vectors), CVE aliases, affected version ranges, and the fixed versions listed for the queried package. Use osv_list_ecosystems to validate the ecosystem string before querying — ecosystem strings are case-sensitive exact matches and an invalid value returns an error, not empty results.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"ecosystem": {
"description": "Ecosystem identifier. Must be an exact match (case-sensitive). Use osv_list_ecosystems to see valid values. Examples: \"npm\", \"PyPI\", \"crates.io\", \"Go\", \"Maven\", \"NuGet\".",
"pattern": "\\S",
"type": "string"
},
"name": {
"description": "Package name as it appears in the ecosystem (e.g. \"express\", \"requests\", \"serde\"). Case-sensitive.",
"pattern": "\\S",
"type": "string"
},
"version": {
"description": "Package version to check (e.g. \"4.17.1\", \"3.1.4\", \"1.0.0\"). Must be an exact version string, not a range.",
"pattern": "\\S",
"type": "string"
}
},
"required": [
"name",
"ecosystem",
"version"
],
"type": "object"
},
"name": "osv_query_package",
"outputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"anyOf": [
{
"not": {
"required": [
"error"
]
},
"required": [
"vulns",
"truncated",
"queryMeta"
]
},
{
"required": [
"error"
]
}
],
"properties": {
"effectiveQuery": {
"description": "The package@version (ecosystem) tuple as queried, echoed for content-only clients.",
"type": "string"
},
"error": {
"additionalProperties": {},
"description": "Present when the call failed. Absent on success.",
"properties": {
"code": {
"description": "JSON-RPC error code for this failure.",
"maximum": 9007199254740991,
"minimum": -9007199254740991,
"type": "integer"
},
"data": {
"additionalProperties": {},
"properties": {
"reason": {
"description": "Machine-readable failure mode. Declared by this tool: `invalid_ecosystem`: The ecosystem string is not recognized by OSV. Ecosystem names are case-sensitive exact matches. Other values are possible when a failure originates below the handler.",
"examples": [
"invalid_ecosystem"
],
"type": "string"
},
"recovery": {
"additionalProperties": {},
"description": "Actionable next step for the caller.",
"properties": {
"hint": {
"type": "string"
}
},
"required": [
"hint"
],
"type": "object"
},
"retryable": {
"description": "Whether retrying may succeed.",
"type": "boolean"
}
},
"type": "object"
},
"message": {
"description": "Human-readable description of what went wrong.",
"type": "string"
}
},
"required": [
"code",
"message"
],
"type": "object"
},
"notice": {
"description": "Present on the clean path — confirms no known vulnerabilities for the queried package.",
"type": "string"
},
"queryMeta": {
"additionalProperties": false,
"description": "Query parameters as submitted.",
"properties": {
"ecosystem": {
"description": "Queried ecosystem.",
"type": "string"
},
"package": {
"description": "Queried package name.",
"type": "string"
},
"version": {
"description": "Queried version.",
"type": "string"
},
"vulnCount": {
"description": "Number of vulnerabilities found.",
"type": "number"
}
},
"required": [
"package",
"ecosystem",
"version",
"vulnCount"
],
"type": "object"
},
"truncated": {
"description": "True when OSV returned more result pages than the fetch cap could follow — the vulnerability list may be INCOMPLETE. A truncated empty list is NOT a clean result; raise OSV_QUERY_MAX_PAGES or narrow the query.",
"type": "boolean"
},
"vulns": {
"description": "Vulnerabilities matching this package version. An empty array means no known vulnerabilities ONLY when truncated is false.",
"items": {
"additionalProperties": false,
"description": "One vulnerability record.",
"properties": {
"affectedRanges": {
"description": "Version ranges affected by this vulnerability.",
"items": {
"additionalProperties": false,
"description": "One affected version range.",
"properties": {
"ecosystem": {
"description": "Affected package ecosystem. Empty for source-only advisory ranges.",
"type": "string"
},
"events": {
"description": "Ordered event boundaries for this range — the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.",
"items": {
"additionalProperties": false,
"description": "One ordered range event.",
"properties": {
"type": {
"description": "Event boundary type: \"introduced\", \"fixed\", \"last_affected\", or \"limit\".",
"type": "string"
},
"value": {
"description": "Version string or commit identifier at this boundary.",
"type": "string"
}
},
"required": [
"type",
"value"
],
"type": "object"
},
"type": "array"
},
"fixed": {
"description": "The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[]).",
"type": "string"
},
"introduced": {
"description": "First affected version (convenience view — see events[]).",
"type": "string"
},
"lastAffected": {
"description": "Last affected version. Present when no fix exists (convenience view — see events[]).",
"type": "string"
},
"packageName": {
"description": "Affected package name (may differ from queried name for umbrella advisories). Empty for source-only advisory ranges.",
"type": "string"
},
"rangeType": {
"description": "\"SEMVER\", \"ECOSYSTEM\", or \"GIT\".",
"type": "string"
},
"repo": {
"description": "Source repository URL for GIT ranges. Absent on version ranges.",
"type": "string"
},
"versions": {
"description": "Explicit affected versions listed on this package entry. Absent or empty when affected versions are expressed only as ranges.",
"items": {
"description": "An explicitly-listed affected version.",
"type": "string"
},
"type": "array"
}
},
"required": [
"packageName",
"ecosystem",
"rangeType"
],
"type": "object"
},
"type": "array"
},
"aliases": {
"description": "Alternative IDs — typically CVE IDs (e.g. [\"CVE-2020-28500\"]). Accepted by nist-nvd-mcp-server for CVSS scores, EPSS, and CISA KEV status.",
"items": {
"description": "A CVE ID or other alias.",
"type": "string"
},
"type": "array"
},
"cweIds": {
"description": "CWE weakness IDs (e.g. [\"CWE-79\", \"CWE-94\"]). Populated on GHSA-sourced records; empty otherwise.",
"items": {
"description": "A CWE ID string.",
"type": "string"
},
"type": "array"
},
"fixedVersions": {
"description": "Every fixed version the advisory lists for the queried package, in record order. A multi-interval range contributes one per interval (typically one per release line); affectedRanges shows which interval each one closes. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package.",
"items": {
"description": "A version that fixes the vulnerability for the queried package.",
"type": "string"
},
"type": "array"
},
"id": {
"description": "OSV vulnerability ID (e.g. \"GHSA-29mw-wpgm-hmr9\", \"PYSEC-2024-1\"). Pass to osv_get_vulnerability to retrieve the full advisory record.",
"type": "string"
},
"modified": {
"description": "ISO 8601 timestamp of last modification.",
"type": "string"
},
"published": {
"description": "ISO 8601 timestamp when the advisory was published.",
"type": "string"
},
"severity": {
"description": "Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for advisories not yet scored and for advisories that score each affected package separately — severitySource then carries the queried package entry used.",
"items": {
"additionalProperties": false,
"description": "One record-level severity entry.",
"properties": {
"score": {
"description": "CVSS vector string (e.g. \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\"), or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\".",
"type": "string"
},
"type": {
"description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\".",
"type": "string"
}
},
"required": [
"type",
"score"
],
"type": "object"
},
"type": "array"
},
"severityLabel": {
"description": "Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses the queried package's affected-level severity entries when the record-level list is empty. Null when no source yields a label.",
"type": [
"string",
"null"
]
},
"severitySource": {
"anyOf": [
{
"additionalProperties": false,
"properties": {
"computedScore": {
"description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
"type": "number"
},
"score": {
"description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.",
"type": "string"
},
"type": {
"description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.",
"enum": [
"database_specific",
"Ubuntu",
"CVSS_V3",
"CVSS_V4"
],
"type": "string"
}
},
"required": [
"type",
"score"
],
"type": "object"
},
{
"type": "null"
}
],
"description": "The severity entry severityLabel was derived from. Null exactly when the label is."
},
"summary": {
"description": "One-line vulnerability description.",
"type": "string"
}
},
"required": [
"id",
"summary",
"aliases",
"severity",
"severityLabel",
"severitySource",
"fixedVersions",
"affectedRanges",
"cweIds",
"published",
"modified"
],
"type": "object"
},
"type": "array"
}
},
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:159a7a00df5d92f4c7ea724fc6de5e164f221c691729115625b34349852fbb60 | sha256sum