Package lookups
Four routes that start from a package name rather than a CVE id or a query. They answer from different upstreams and are grouped here because a command-line tool holding a package name reaches for them in turn.
GET /api/v1/packages/index
GET /api/v1/search/package/:name
GET /api/v1/package/:name/history
GET /api/v1/package/:name/prsFor a single package version by Package URL, see /purl/:purl on the SBOM analysis page. For OSV records alone, see OSV vulnerabilities; for nixpkgs-specific matching with confidence, CVE matching.
Every package this API can answer for
GET /api/v1/packages/indexA flat JSON array of package names with at least one advisory recorded, for clients that want to check membership locally rather than probe per package. There is no envelope. Cached for an hour.
["389-ds-base", "7zz", "a2ps", "accountsservice", "actual-server", "..."]Vulnerabilities affecting a package, across sources
GET /api/v1/search/package/:name?ecosystem=npm&version=4.17.20CVEs and advisories naming the package, merged across the sources that answered and deduplicated by id.
| Parameter | In | Required | Description |
|---|---|---|---|
name | path | Yes | Package name, scoped npm names included (@scope/name). At most 200 characters drawn from letters, digits, ., -, _ and /. |
ecosystem | query | No | OSV ecosystem (npm, PyPI, Go, ...). |
version | query | No | Keep only advisories whose affected ranges include this version, where a source states ranges. |
{
"success": true,
"data": {
"package": "lodash",
"version": "",
"ecosystem": "npm",
"vulnerabilities": [
{
"cve_id": "CVE-2024-38986",
"title": "Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code ...",
"description": "...",
"severity": "critical",
"score": 9.8,
"published": "2024-07-30T20:15:03.990",
"source": "nvd",
"affected_versions": []
}
],
"count": 19,
"partial": false,
"failedSources": []
},
"timestamp": "2026-09-28T01:04:30.512Z"
}count is a floor when partial is true: the sources named in failedSources were not heard, so a short list is not a clean one. A name with characters package names never carry answers 400.
OSV history for a package
GET /api/v1/package/:name/history?ecosystem=npmEvery vulnerability OSV.dev lists for the package, newest first by published date.
{
"success": true,
"data": {
"package": "lodash",
"ecosystem": "npm",
"totalVulnerabilities": 12,
"vulnerabilities": [
{
"id": "GHSA-29mw-wpgm-hmr9",
"summary": "Regular Expression Denial of Service (ReDoS) in lodash",
"severity": "MODERATE",
"published": "2022-01-06T20:30:46Z",
"modified": "2024-04-15T18:12:09Z",
"affected": [{ "versions": [], "ranges": [] }]
}
]
},
"timestamp": "2026-09-28T01:05:52.318Z"
}A bare name that exists in several ecosystems (lodash, requests) cannot be resolved by OSV and answers 400 asking for one. ecosystem reads all in the body when none was given.
Recent nixpkgs pull requests mentioning a package
GET /api/v1/package/:name/prsThe ten most recently updated nixpkgs pull requests whose text mentions the package, from GitHub search, cached for two hours. A mention is a search hit and not a statement that the pull request changes the package.
{
"success": true,
"data": [
{
"number": 550095,
"title": "nixos/comfyui: add acceleration, models and extraPackages options",
"author": "knightfemale",
"state": "open",
"createdAt": "2026-08-07T06:00:41Z",
"url": "https://github.com/NixOS/nixpkgs/pull/550095",
"labels": ["6.topic: nixos", "8.has: documentation"]
}
],
"total": 214,
"timestamp": "2026-09-28T01:05:57.902Z"
}total is GitHub's count of matching pull requests, of which at most ten are returned. A GitHub failure answers 502 with data: null rather than an empty list, so an outage is never read as no pull requests.