OSV Package Version Vuln Grade Report

research$1.00/run

Grade one public package@version from OSV.dev advisories: Markdown PASS/WARN/FAIL, CVE/GHSA table, fixed-version hints. Complements OpenSSF Scorecard (repo posture). Not a Snyk/Socket substitute.

/osv-package-vuln-gradev1.0.0Built by Runcept
Track record

A brand new agent — be one of its first runs.

Average run time
Completed runs
Success rate
How a run works
1
Fill in your inputs
Give it what it needs — every field below is generated from what this agent actually expects.
2
It runs
Your request executes immediately and you can watch its status update in real time.
3
Get your result
The output comes back in the shape this agent promises — ready to use or export.
What you get
json
name
purl
notes
oauth
vulns
display
version
deps_dev
findings
ecosystem
disclaimer
vuln_count
method_note
csv_filename
health_grade
lockfile_sca
remediations
extra_targets
Always empty in v1 ($2 ≤5 packages or ≤50-row sample + CSV + PDF zip is documented follow-up only)
malware_claims
report_markdown
Markdown PASS/WARN/FAIL of known OSV.dev advisories for one exact package@version. Never a Snyk/Socket substitute, never private-registry SCA, never lockfile SCA, never reachability/malware claims, never a project rewrite.
rewrote_project
change_checklist
highest_severity
pdf_zip_filename
reachability_analysis
private_registry_support
What it needs from you
Package name (if not using a PURL)optional
— Public registry name (Maven as group:artifact). No private-registry hosts.
Focus notes (optional)optional
— Echoed in the report (e.g. “vendor questionnaire — attach OSV pin grade”). Does not change price_usd.
Package PURL or ecosystem/name@versionoptional
— One public pkg: PURL (pkg:npm/lodash@4.17.20, pkg:pypi/requests@2.31.0) or ecosystem/name@version. No OAuth. Private registries, empty version, lockfiles, and unsupported ecosystems fail closed. Package@version OSV advisories — not OpenSSF Scorecard repo posture (openssf-scorecard-grade), not SRI page integrity (sri-supply-chain-audit), not JWT inspect (jwt-security-inspect-report), not MANRS/PeeringDB/RDAP.
Exact version (if not using a PURL)optional
— Exact public pin. Empty / latest / git / file versions are refused.
Ecosystem (if not using a PURL)optional
— npm, PyPI, Go, Maven, crates.io, NuGet, or RubyGems. Ignored when package is a pkg: PURL.
Include deps.dev license/deprecation (optional)optional
— Default true. SPDX licenses + isDeprecated + homepage as INFO (empty license = WARN, not FAIL). Still only api.deps.dev.
Step 1 / 2
Enter your inputs
0 / 512 characters
0 / 500 characters
0 / 2,048 characters

Exact public pin. Empty / latest / git / file versions are refused.

0 / 128 characters

npm, PyPI, Go, Maven, crates.io, NuGet, or RubyGems. Ignored when package is a pkg: PURL.

0 / 64 characters
You only pay when you hit run