How to get OSV Lockfile Advisory Lookup in an AI tool
Query the public OSV.dev API for known vulnerabilities on package pins (npm/PyPI and more). A run saves one row per result.
Set up the Apify actor
Apify is where this run is collected. An actor is the program that collects the rows. A task is that program saved with your settings, so the next section can ask for the latest rows. You need a free Apify account.
- 01Open OSV Lockfile Advisory Lookup and click Try for free. Create an Apify account if you do not have one. The Free plan does not ask for a card.
- 02You are on the input form. Keep the sample for this first run.
{ "packages": [ { "ecosystem": "npm", "name": "lodash", "version": "4.17.20" } ], "maxItems": 5 } - 03Leave the proxy setting as it is. Click Start and wait until the run says Succeeded.
- 04Open Storage, then Dataset. You should see
ecosystem,packageName,packageVersion,vulnId. - 05When you want the real list, raise maxItems. The sample cap is only there so the first run stays small.
- 06Go back to the input and choose Save as a new task. Name it after this list.
- 07Open the task. Copy the task ID from the address bar. Excel, Sheets, Power BI, and the other guides ask for this ID.
- 08On the task, open Schedules and add a weekly run if you want fresh rows. Each run pays the start charge and the charge for the rows. The amounts are in the price list on this page.
- 09Open Settings, then API & Integrations, and copy an API token. Excel, Sheets, and the other guides put this token in a download link. Anyone with that link can download the rows, so treat it like a password.
How to set up in an AI tool
Use the task ID and the API token from Set up the Apify actor, above.
- 01Open the API tab on OSV Lockfile Advisory Lookup.
- 02Copy the MCP config, or call the run endpoint with the API token from Set up the Apify actor, above.
- 03Ask for
ecosystem,packageName,packageVersion,vulnId,summary. A schedule still lives on the task from Set up the Apify actor, above.
Schema
Examples come from the actor sample, not a live result.
| Name | Description | Example |
|---|---|---|
ecosystem | Ecosystem | npm |
packageName | Package name | lodash |
packageVersion | Package version | 4.17.20 |
vulnId | Vuln ID | GHSA-29mw-wpgm-hmr9 |
summary | Advisory summary | Regular |
sourceUrl | Source URL | https:/ |
scrapedAt | Scraped at | 2026-09-29T12:00:00+00:00 |
ecosystemEcosystemnpmpackageNamePackage namelodashpackageVersionPackage version4.17.20vulnIdVuln IDGHSA-29mw-wpgm-hmr9summaryAdvisory summaryRegularExpression Denial of Service (ReDoS) in lodash sourceUrlSource URLhttps:// osv.dev/ vulnerability/ GHSA-29mw-wpgm-hmr9 scrapedAtScraped at2026-09-29T12:00:00+00:00