
OSV Advisories
io.github.basitalisandhuv0.1.1更新於 Oct 5, 2026
Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.
概覽
讓助理在 OSV.dev 資料庫中查詢套件與版本的已知漏洞,並批次掃描相依性鎖定檔。
- 功能
- 提供四個工具:query_package 依生態系、名稱與選用版本回傳單一套件的完整公告,包含 CVE 別名、嚴重程度、受影響範圍與修正版本;query_batch 為最多 1000 個套件回傳公告編號;scan_lockfile 解析 package-lock.json、requirements.txt、poetry.lock 或 go.sum,並批次查詢其中所有固定版本的套件,同時列出被略過的項目;get_vulnerability 回傳單一公告的完整內容。所有查詢都透過 HTTPS 送往 api.osv.dev。
- 適用情境
- 適合在檢查某個相依套件或整份鎖定檔是否有已知漏洞時使用,例如相依性審查、升級規劃,或快速稽核專案中固定版本的套件。
- 執行需求
- 透過 stdio 在本機執行;README 提供以 npx 或 Docker 映像安裝的方式,也可在取出原始碼後用 Node.js 執行 npm install 與 npm run build。未宣告任何帳號、API 金鑰或環境變數。需要能連線至 api.osv.dev 的網路。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 OSV Advisories,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
osv-advisories MCP server
Looks up known vulnerabilities in the OSV.dev database by package name, version and ecosystem, and scans lockfiles. The only host it ever contacts is api.osv.dev over HTTPS, with a 15 s timeout per request and an 8 MB cap per response.
Part of dev-mcp-servers. Stdio transport only; the server never opens a port.
Tools
Install
Claude Code:
Add -s user to make it available in every project. Any client that reads .mcp.json (Claude Code, Claude Desktop, Cursor):
Pin the version as shown so that an update to the package cannot change what runs in your editor without you noticing. From a checkout, use "command": "node", "args": ["<path>/packages/osv-advisories/dist/index.js"] after npm install && npm run build at the repository root.
What it touches
- Network:
https://api.osv.devonly. Any other origin is refused before a request is made. Redirects are refused. No telemetry. - Local files:
scan_lockfilereads the one file you name, up to 10 MB. - Telemetry: none.
Notes
- Ecosystem names are matched case-insensitively against the OSV list and normalised (
pypibecomesPyPI); unknown names are an error rather than an empty result. - For Go modules the leading
vis stripped from versions, as OSV expects. - An empty result means OSV has no advisory for that exact package and version; it does not prove the package is safe.
Build and test
Tests use node:test and the SDK's in-memory transport; they do not reach the network.
Licence
MIT. See LICENSE.
來源:packages/osv-advisories/README.md,提交 58c8c95
工具
0版本歷史
1- v0.1.1最新Oct 5, 2026


