How to get OSV Lockfile Advisory Lookup
Query the public OSV.dev API for known vulnerabilities on package pins (npm/PyPI and more). A run saves one row per result.
One row per result
A row has Ecosystem, Package name, Package version, Vuln ID. The columns are listed in the schema on this page.
The next run
Put the run on a schedule and the next file is the latest rows.
OSV Lockfile Advisory Lookup in Excel, Sheets, or Power BI
The rows are the same in each of those tools. The guide for the one you already use starts with a free Apify account and finishes with the file.
Schema
Examples come from the actor sample, not a live result.
| Name | Description | Example |
|---|---|---|
ecosystem | Ecosystem | npm |
packageName | Package name | lodash |
packageVersion | Package version | 4.17.20 |
vulnId | Vuln ID | GHSA-29mw-wpgm-hmr9 |
summary | Advisory summary | Regular |
sourceUrl | Source URL | https:/ |
scrapedAt | Scraped at | 2026-09-29T12:00:00+00:00 |
ecosystemEcosystemnpmpackageNamePackage namelodashpackageVersionPackage version4.17.20vulnIdVuln IDGHSA-29mw-wpgm-hmr9summaryAdvisory summaryRegularExpression Denial of Service (ReDoS) in lodash sourceUrlSource URLhttps:// osv.dev/ vulnerability/ GHSA-29mw-wpgm-hmr9 scrapedAtScraped at2026-09-29T12:00:00+00:00