Home

OSV Lockfile Advisory Lookup

How to get OSV Lockfile Advisory Lookup in Make

Query the public OSV.dev API for known vulnerabilities on package pins (npm/PyPI and more). A run saves one row per result.

Set up the Apify actor

Apify is where this run is collected. An actor is the program that collects the rows. A task is that program saved with your settings, so the next section can ask for the latest rows. You need a free Apify account.

  1. 01
    Open OSV Lockfile Advisory Lookup and click Try for free. Create an Apify account if you do not have one. The Free plan does not ask for a card.
  2. 02
    You are on the input form. Keep the sample for this first run.
    {
        "packages": [
            {
                "ecosystem": "npm",
                "name": "lodash",
                "version": "4.17.20"
            }
        ],
        "maxItems": 5
    }
  3. 03
    Leave the proxy setting as it is. Click Start and wait until the run says Succeeded.
  4. 04
    Open Storage, then Dataset. You should see ecosystem, packageName, packageVersion, vulnId.
  5. 05
    When you want the real list, raise maxItems. The sample cap is only there so the first run stays small.
  6. 06
    Go back to the input and choose Save as a new task. Name it after this list.
  7. 07
    Open the task. Copy the task ID from the address bar. Excel, Sheets, Power BI, and the other guides ask for this ID.
  8. 08
    On the task, open Schedules and add a weekly run if you want fresh rows. Each run pays the start charge and the charge for the rows. The amounts are in the price list on this page.
  9. 09
    Open Settings, then API & Integrations, and copy an API token. Excel, Sheets, and the other guides put this token in a download link. Anyone with that link can download the rows, so treat it like a password.

How to set up in Make

Use the task ID and the API token from Set up the Apify actor, above.

  1. 01
    In your Make scenario, add a module and search Apify. Choose Run an Actor.
  2. 02
    Connect your Apify account with OAuth. If Make asks for a token, paste the API token from Set up the Apify actor, above.
  3. 03
    Select OSV Lockfile Advisory Lookup. Set Run synchronously to Yes for a small sample. Paste this input.
    {
        "packages": [
            {
                "ecosystem": "npm",
                "name": "lodash",
                "version": "4.17.20"
            }
        ],
        "maxItems": 5
    }
  4. 04
    Add Get Dataset Items. For Dataset ID, choose the default dataset ID from the Run an Actor module.
  5. 05
    Map ecosystem, packageName, packageVersion, vulnId, summary into the next module. A weekly repeat is the schedule from Set up the Apify actor, above.

Schema

Examples come from the actor sample, not a live result.

NameDescriptionExample
ecosystemEcosystemnpm
packageNamePackage namelodash
packageVersionPackage version4.17.20
vulnIdVuln IDGHSA-29mw-wpgm-hmr9
summaryAdvisory summaryRegular Expression Denial of Service (ReDoS) in lodash
sourceUrlSource URLhttps://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9
scrapedAtScraped at2026-09-29T12:00:00+00:00
  • ecosystemEcosystemnpm
  • packageNamePackage namelodash
  • packageVersionPackage version4.17.20
  • vulnIdVuln IDGHSA-29mw-wpgm-hmr9
  • summaryAdvisory summaryRegular Expression Denial of Service (ReDoS) in lodash
  • sourceUrlSource URLhttps://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9
  • scrapedAtScraped at2026-09-29T12:00:00+00:00