Home

How to get OSV Lockfile Advisory Lookup

Query the public OSV.dev API for known vulnerabilities on package pins (npm/PyPI and more). A run saves one row per result.

One row per result

A row has Ecosystem, Package name, Package version, Vuln ID. The columns are listed in the schema on this page.

The next run

Put the run on a schedule and the next file is the latest rows.

OSV Lockfile Advisory Lookup in Excel, Sheets, or Power BI

The rows are the same in each of those tools. The guide for the one you already use starts with a free Apify account and finishes with the file.

Schema

Examples come from the actor sample, not a live result.

NameDescriptionExample
ecosystemEcosystemnpm
packageNamePackage namelodash
packageVersionPackage version4.17.20
vulnIdVuln IDGHSA-29mw-wpgm-hmr9
summaryAdvisory summaryRegular Expression Denial of Service (ReDoS) in lodash
sourceUrlSource URLhttps://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9
scrapedAtScraped at2026-09-29T12:00:00+00:00
  • ecosystemEcosystemnpm
  • packageNamePackage namelodash
  • packageVersionPackage version4.17.20
  • vulnIdVuln IDGHSA-29mw-wpgm-hmr9
  • summaryAdvisory summaryRegular Expression Denial of Service (ReDoS) in lodash
  • sourceUrlSource URLhttps://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9
  • scrapedAtScraped at2026-09-29T12:00:00+00:00