
OSV Advisories
io.github.basitalisandhuv0.1.1更新于 Oct 5, 2026
Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.
概览
让助手在 OSV.dev 数据库中查询软件包和版本的已知漏洞,并批量扫描依赖锁文件。
- 功能
- 提供四个工具:query_package 按生态、名称和可选版本返回单个软件包的完整公告,包括 CVE 别名、严重程度、受影响范围和修复版本;query_batch 为最多 1000 个软件包返回公告编号;scan_lockfile 解析 package-lock.json、requirements.txt、poetry.lock 或 go.sum,并批量查询其中所有固定版本的软件包,同时列出被跳过的条目;get_vulnerability 返回单条公告的完整内容。所有查询都通过 HTTPS 发往 api.osv.dev。
- 适用场景
- 适合在检查某个依赖或整个锁文件是否存在已知漏洞时使用,例如依赖审查、升级规划或快速审计项目中固定版本的软件包。
- 运行要求
- 通过 stdio 在本地运行;README 给出用 npx 或 Docker 镜像安装的方式,也可在检出代码后用 Node.js 执行 npm install 和 npm run build。未声明任何账户、API 密钥或环境变量。需要能访问 api.osv.dev 的网络。
安装
在 SourceWeft 中
- 打开 控制台中的 OSV Advisories,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
osv-advisories MCP server
Looks up known vulnerabilities in the OSV.dev database by package name, version and ecosystem, and scans lockfiles. The only host it ever contacts is api.osv.dev over HTTPS, with a 15 s timeout per request and an 8 MB cap per response.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/osv-advisories/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network:
https://api.osv.devonly. Any other origin is refused before a request is made. Redirects are refused. No telemetry. - Local files:
scan_lockfilereads the one file you name, up to 10 MB. - Telemetry: none.
Notes
- Ecosystem names are matched case-insensitively against the OSV list and normalised (
pypibecomesPyPI); unknown names are an error rather than an empty result. - For Go modules the leading
vis stripped from versions, as OSV expects. - An empty result means OSV has no advisory for that exact package and version; it does not prove the package is safe.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
来源:packages/osv-advisories/README.md,提交 58c8c95
工具
0版本历史
1- v0.1.1最新Oct 5, 2026


