OSV.dev
The vulnerability database and API behind the OSV schema — aggregates advisories across ecosystems and serves them in one consistent format.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| OSV Schema | stores |
- Interfaces
http-apiweb-ui- Invoke
curl -sX POST https://api.osv.dev/v1/query -d '{"package":{"name":"<pkg>","ecosystem":"<eco>"}}'- Emits
- json
- Runtime
- Needs network Non-deterministic Read-only No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
A free, unauthenticated JSON API — one of the easiest external data sources for an agent to consult mid-task.
- Website
- https://osv.dev
- Repository
- https://github.com/google/osv.dev
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 2926 · last commit 2026-09-16
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.