nixpkgs vulnerabilities in OSV format
OSV.dev covers dozens of ecosystems, from npm and PyPI to Debian and Alpine, but it has no Nix or nixpkgs ecosystem. There is no public OSV feed for the software NixOS and Nix users actually run. Vulnpatch builds one and publishes it here, so any tool that reads the OSV schema can read nixpkgs vulnerabilities too.
This feed is Vulnpatch's own work. It is not published by OSV.dev or by the NixOS project, and the ecosystem string it uses, Nixpkgs, is not registered with OSV.
Endpoints
GET /api/v1/feed/osv/nixpkgs
GET /api/v1/cve/:id/osvThe bulk feed returns every record at once. The per-CVE endpoint returns one record, or a 404 with code NO_ADJUDICATED_MAPPING when no nixpkgs security evidence backs a mapping for that CVE.
What a record contains
Each record is an OSV record keyed by its CVE id. Package names are nixpkgs attribute names, and each affected entry says which channels were checked and the version each carried.
{
"schema_version": "1.9.0",
"id": "CVE-2026-86191",
"modified": "2026-07-20T13:14:09.600690Z",
"summary": "SiYuan before v3.8.2 Private Attribute View Key Enumeration",
"affected": [{
"package": { "ecosystem": "Nixpkgs", "name": "siyuan" },
"database_specific": {
"evidence": "tracker_adjudication",
"channels": {
"nixos-26.05": { "version": "3.6.5", "status": "unknown" },
"nixos-unstable": { "version": "3.6.5", "status": "unknown" }
}
}
}]
}Where the records come from
Today the feed carries the matches the nixpkgs security review has published: a person on the NixOS security team looked at the CVE, matched it to nixpkgs attributes and published the match. Each affected entry names its evidence in database_specific.evidence:
evidence | Meaning |
|---|---|
tracker_adjudication | Matched and published by the nixpkgs security review |
tracker_issue | A nixpkgs security issue on GitHub names the attribute: the security tracker listed it in the issue, or a person's issue title names it and the nixpkgs package index confirms the attribute exists in a tracked channel |
Weaker signals never become findings. Matches still awaiting review, attributes Vulnpatch derived through Repology or search.nixos.org, and a package name read from an issue title that the package index does not confirm (tracker_issue_title) travel in database_specific.vulnpatch.candidates, where a scanner will not report them. Matches the review rejected are listed as rejected. The evidence values keep their original names, since tools already depend on them.
Every record's references begin with the CVE Program's record for the id, followed by the match it was built from and, for records built from a dossier, the dossier's own references.
Reading the feed honestly
The bulk response carries its own coverage:
| Field | Meaning |
|---|---|
count | Records in this response |
upstreamTotal | Published matches the review holds |
notYetCarried | Published matches not yet converted |
unconvertible | Published matches with no CVE id or no attribute, which cannot become OSV records |
complete | Whether every convertible match is carried |
coverageNote | The same in words |
attribution | The sources to credit and their terms, the same as the Terms section below, carried in the response so a tool never has to open this page |
license | CC-BY-4.0: the licence over the feed itself |
terms | Vulnpatch's licence, a citation for the feed and the notice each source asks a consumer to carry |
While complete is false, the absence of a record is not evidence that a package is unaffected. If the feed has not been built at all, the endpoint answers 503 with code FEED_NOT_READY rather than an empty list, so an unbuilt feed never reads as "nixpkgs has no vulnerabilities".
What comes next
Vulnpatch is building a history of nixpkgs itself: which version of each attribute every channel carried, and when a fix reached each channel, to the minute where the channel's own record allows. When it is ready, records here will state affected and fixed versions per channel for every mapped CVE, not only the reviewed ones, each with the evidence behind it.
Terms
The feed is Vulnpatch's own work and is licensed CC BY 4.0. The records combine the CVE Program's records, nixpkgs metadata and the nixpkgs security review's published matches, each linked from the record and each under its own terms: the CVE terms of use, which ask every copy to carry MITRE's copyright designation and the licence; nixpkgs's MIT licence; and the facts-and-links rule for GitHub issue content. Credit them when you republish, and cite the feed as terms.citation states. Each record carries the same notices in database_specific.vulnpatch.terms, so a record copied out of the feed keeps them. The full table is on the data terms page.