OSV Advisories

io.github.basitalisandhuv0.1.1更新於 Oct 5, 2026

Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.

概覽

AI 產生的概覽

讓助理在 OSV.dev 資料庫中查詢套件與版本的已知漏洞,並批次掃描相依性鎖定檔。

功能
提供四個工具:query_package 依生態系、名稱與選用版本回傳單一套件的完整公告,包含 CVE 別名、嚴重程度、受影響範圍與修正版本;query_batch 為最多 1000 個套件回傳公告編號;scan_lockfile 解析 package-lock.json、requirements.txt、poetry.lock 或 go.sum,並批次查詢其中所有固定版本的套件,同時列出被略過的項目;get_vulnerability 回傳單一公告的完整內容。所有查詢都透過 HTTPS 送往 api.osv.dev。
適用情境
適合在檢查某個相依套件或整份鎖定檔是否有已知漏洞時使用,例如相依性審查、升級規劃,或快速稽核專案中固定版本的套件。
執行需求
透過 stdio 在本機執行;README 提供以 npx 或 Docker 映像安裝的方式,也可在取出原始碼後用 Node.js 執行 npm install 與 npm run build。未宣告任何帳號、API 金鑰或環境變數。需要能連線至 api.osv.dev 的網路。
安裝前請注意
scan_lockfile 會讀取你指定的一個本機檔案,最大 10 MB,並把其中固定版本的套件名稱與版本送往 api.osv.dev。結果為空只代表 OSV 對該確切套件與版本沒有公告,並不證明該套件安全。請依 README 的建議固定套件版本,以免更新在你不注意時改變實際執行的內容。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 OSV Advisories,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

osv-advisories MCP server

Looks up known vulnerabilities in the OSV.dev database by package name, version and ecosystem, and scans lockfiles. The only host it ever contacts is api.osv.dev over HTTPS, with a 15 s timeout per request and an 8 MB cap per response.

Part of dev-mcp-servers. Stdio transport only; the server never opens a port.

Tools

ToolInputWhat it returns
query_packageecosystem, name, version?Full advisories for one package: ids, aliases (CVE), summary, severity, affected ranges, fixed versions, references. POST /v1/query, up to five pages.
query_batchpackages[] (up to 1000)Advisory ids per package. POST /v1/querybatch in chunks of 100.
scan_lockfilepath or content, filename?, format?, include_details?Parses package-lock.json (v1 to v3), requirements.txt (== pins only), poetry.lock or go.sum (basic) and batch-queries every pinned package; lists skipped entries. Reads one local file up to 10 MB.
get_vulnerabilityidOne advisory in full. GET /v1/vulns/{id}.

Install

Claude Code:

bash
claude mcp add osv-advisories -- npx -y @basitalisandhu/[email protected]

Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):

json
{  "mcpServers": {    "osv-advisories": {      "command": "npx",      "args": ["-y", "@basitalisandhu/[email protected]"]    }  }}

Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/osv-advisories/dist/index.js"] after npm install && npm run build at the repository root.

What it touches

  • Network: https://api.osv.dev only. Any other origin is refused before a request is made. Redirects are refused. No telemetry.
  • Local files: scan_lockfile reads the one file you name, up to 10 MB.
  • Telemetry: none.

Notes

  • Ecosystem names are matched case-insensitively against the OSV list and normalised (pypi becomes PyPI); unknown names are an error rather than an empty result.
  • For Go modules the leading v is stripped from versions, as OSV expects.
  • An empty result means OSV has no advisory for that exact package and version; it does not prove the package is safe.

Build and test

bash
npm install        # at the repository rootnpm run build -w @basitalisandhu/mcp-osv-advisoriesnpm test -w @basitalisandhu/mcp-osv-advisories

Tests use node:test and the SDK's in-memory transport; they do not reach the network.

Licence

MIT. See LICENSE.

來源:packages/osv-advisories/README.md,提交 58c8c95

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.1最新Oct 5, 2026