OSV Advisories

io.github.basitalisandhuv0.1.1Updated Oct 5, 2026

Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant look up known vulnerabilities for packages and versions in the OSV.dev database and scan dependency lockfiles in batch.

What it does
Provides four tools: query_package returns full advisories for one package by ecosystem, name and optional version, including CVE aliases, severity, affected ranges and fixed versions; query_batch returns advisory ids for up to 1000 packages; scan_lockfile parses package-lock.json, requirements.txt, poetry.lock or go.sum and batch-queries every pinned package, listing skipped entries; get_vulnerability returns one advisory in full. All lookups go to api.osv.dev over HTTPS.
When to use it
Useful when checking whether a dependency or a whole lockfile has known advisories, for example during dependency review, upgrade planning or a quick audit of a project's pinned packages.
Requirements
Runs locally over stdio; the README shows installation via npx or a Docker image, or from a checkout with Node.js after npm install and npm run build. No accounts, API keys or environment variables are declared. Network access to api.osv.dev is required.
Before you install
scan_lockfile reads one local file you name, up to 10 MB, and sends the pinned package names and versions to api.osv.dev. An empty result only means OSV has no advisory for that exact package and version, not that the package is safe. Pin the package version as the README advises so an update cannot change what runs.

Installation

In SourceWeft

  1. Open OSV Advisories in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

osv-advisories MCP server

Looks up known vulnerabilities in the OSV.dev database by package name, version and ecosystem, and scans lockfiles. The only host it ever contacts is api.osv.dev over HTTPS, with a 15 s timeout per request and an 8 MB cap per response.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
query_packageecosystem, name, version?Full advisories for one package: ids, aliases (CVE), summary, severity, affected ranges, fixed versions, references. POST /v1/query, up to five pages.
query_batchpackages[] (up to 1000)Advisory ids per package. POST /v1/querybatch in chunks of 100.
scan_lockfilepath or content, filename?, format?, include_details?Parses package-lock.json (v1 to v3), requirements.txt (== pins only), poetry.lock or go.sum (basic) and batch-queries every pinned package; lists skipped entries. Reads one local file up to 10 MB.
get_vulnerabilityidOne advisory in full. GET /v1/vulns/{id}.

Install

Claude Code:

bash
claude mcp add osv-advisories -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "osv-advisories": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/osv-advisories/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: https://api.osv.dev only. Any other origin is refused before a request is made. Redirects are refused. No telemetry.
  • Local files: scan_lockfile reads the one file you name, up to 10 MB.
  • Telemetry: none.

Notes

  • Ecosystem names are matched case-insensitively against the OSV list and normalised (pypi becomes PyPI); unknown names are an error rather than an empty result.
  • For Go modules the leading v is stripped from versions, as OSV expects.
  • An empty result means OSV has no advisory for that exact package and version; it does not prove the package is safe.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-osv-advisoriesnpm test -w @basitalisandhu/mcp-osv-advisories

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

Source: packages/osv-advisories/README.md at commit 58c8c95

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.1LatestOct 5, 2026