OSV Schema
The JSON schema describing open-source vulnerabilities in a way that is precise about which versions are affected, across every package ecosystem.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| OSV Schema | authors |
- Interfaces
library- Consumes
- json-schema
- Emits
- json
- Runtime
- Runs offline Deterministic Read-only No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
The reason this schema won: version ranges are expressed exactly, so "is my version affected?" is a computation rather than a judgement call about a CVE description.
- Website
- https://ossf.github.io/osv-schema/
- Repository
- https://github.com/ossf/osv-schema
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 271 · last commit 2026-09-15
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.