Browsing as guest
Any OSV id works: CVE, GHSA, PYSEC, GO, RUSTSEC, Bitnami, Debian DSA, Ubuntu USN.
Leave version blank to list every known OSV record for that package. Purl also works in the name field (pkg:npm/lodash@4.17.20).
Queries api.osv.dev in batches (up to 400 packages). Results stay on this account. Advisory data only — not a penetration test.
Source: osv.dev · API https://api.osv.dev · no key required
Add Open Source Vulnerabilities to your Home Screen to open it like an app.
On iPhone use Safari: tap Share, then View More if needed, then Add to Home Screen.