
OSV Advisories
io.github.basitalisandhuv0.1.1Updated Oct 5, 2026
Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.
Overview
Lets an assistant look up known vulnerabilities for packages and versions in the OSV.dev database and scan dependency lockfiles in batch.
- What it does
- Provides four tools: query_package returns full advisories for one package by ecosystem, name and optional version, including CVE aliases, severity, affected ranges and fixed versions; query_batch returns advisory ids for up to 1000 packages; scan_lockfile parses package-lock.json, requirements.txt, poetry.lock or go.sum and batch-queries every pinned package, listing skipped entries; get_vulnerability returns one advisory in full. All lookups go to api.osv.dev over HTTPS.
- When to use it
- Useful when checking whether a dependency or a whole lockfile has known advisories, for example during dependency review, upgrade planning or a quick audit of a project's pinned packages.
- Requirements
- Runs locally over stdio; the README shows installation via npx or a Docker image, or from a checkout with Node.js after npm install and npm run build. No accounts, API keys or environment variables are declared. Network access to api.osv.dev is required.
Installation
In SourceWeft
- Open OSV Advisories in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
osv-advisories MCP server
Looks up known vulnerabilities in the OSV.dev database by package name, version and ecosystem, and scans lockfiles. The only host it ever contacts is api.osv.dev over HTTPS, with a 15 s timeout per request and an 8 MB cap per response.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/osv-advisories/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network:
https://api.osv.devonly. Any other origin is refused before a request is made. Redirects are refused. No telemetry. - Local files:
scan_lockfilereads the one file you name, up to 10 MB. - Telemetry: none.
Notes
- Ecosystem names are matched case-insensitively against the OSV list and normalised (
pypibecomesPyPI); unknown names are an error rather than an empty result. - For Go modules the leading
vis stripped from versions, as OSV expects. - An empty result means OSV has no advisory for that exact package and version; it does not prove the package is safe.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
Source: packages/osv-advisories/README.md at commit 58c8c95
Tools
0Version history
1- v0.1.1LatestOct 5, 2026


