OSV Advisories

io.github.basitalisandhuv0.1.1更新于 Oct 5, 2026

Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.

概览

AI 生成的概览

让助手在 OSV.dev 数据库中查询软件包和版本的已知漏洞,并批量扫描依赖锁文件。

功能
提供四个工具:query_package 按生态、名称和可选版本返回单个软件包的完整公告,包括 CVE 别名、严重程度、受影响范围和修复版本;query_batch 为最多 1000 个软件包返回公告编号;scan_lockfile 解析 package-lock.json、requirements.txt、poetry.lock 或 go.sum,并批量查询其中所有固定版本的软件包,同时列出被跳过的条目;get_vulnerability 返回单条公告的完整内容。所有查询都通过 HTTPS 发往 api.osv.dev。
适用场景
适合在检查某个依赖或整个锁文件是否存在已知漏洞时使用,例如依赖审查、升级规划或快速审计项目中固定版本的软件包。
运行要求
通过 stdio 在本地运行;README 给出用 npx 或 Docker 镜像安装的方式,也可在检出代码后用 Node.js 执行 npm install 和 npm run build。未声明任何账户、API 密钥或环境变量。需要能访问 api.osv.dev 的网络。
安装前请注意
scan_lockfile 会读取你指定的一个本地文件,最大 10 MB,并把其中固定版本的软件包名称和版本发送到 api.osv.dev。结果为空只表示 OSV 对该确切软件包和版本没有公告,并不证明该软件包安全。按 README 的建议固定软件包版本,以免更新在你不注意时改变实际运行的内容。

安装

在 SourceWeft 中

  1. 打开 控制台中的 OSV Advisories,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

osv-advisories MCP server

Looks up known vulnerabilities in the OSV.dev database by package name, version and ecosystem, and scans lockfiles. The only host it ever contacts is api.osv.dev over HTTPS, with a 15 s timeout per request and an 8 MB cap per response.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
query_packageecosystem, name, version?Full advisories for one package: ids, aliases (CVE), summary, severity, affected ranges, fixed versions, references. POST /v1/query, up to five pages.
query_batchpackages[] (up to 1000)Advisory ids per package. POST /v1/querybatch in chunks of 100.
scan_lockfilepath or content, filename?, format?, include_details?Parses package-lock.json (v1 to v3), requirements.txt (== pins only), poetry.lock or go.sum (basic) and batch-queries every pinned package; lists skipped entries. Reads one local file up to 10 MB.
get_vulnerabilityidOne advisory in full. GET /v1/vulns/{id}.

Install

Claude Code:

bash
claude mcp add osv-advisories -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "osv-advisories": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/osv-advisories/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: https://api.osv.dev only. Any other origin is refused before a request is made. Redirects are refused. No telemetry.
  • Local files: scan_lockfile reads the one file you name, up to 10 MB.
  • Telemetry: none.

Notes

  • Ecosystem names are matched case-insensitively against the OSV list and normalised (pypi becomes PyPI); unknown names are an error rather than an empty result.
  • For Go modules the leading v is stripped from versions, as OSV expects.
  • An empty result means OSV has no advisory for that exact package and version; it does not prove the package is safe.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-osv-advisoriesnpm test -w @basitalisandhu/mcp-osv-advisories

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

来源:packages/osv-advisories/README.md,提交 58c8c95

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.1最新Oct 5, 2026