{"slug":"2s-io-api-security-package-7b1f11","title":"Security and provenance for an open-source package, composed live from three aut","host":"2s.io","method":"GET","resource":"https://2s.io/api/security/package","category":"company","description":"Security and provenance for an open-source package, composed live from three authoritative sources in one call. Pass ecosystem (npm, pypi, go, maven, cargo, nuget) + name (+ optional version; defaults to latest). Returns: known vulnerabilities from OSV (osv.dev — aggregates GitHub Security Advisorie","price_listed":0.0054,"price_asked":0.0054,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":249,"reported_calls_30d":3,"reported_payers_30d":2,"networks":["eip155:8453","solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"ecosystem":"npm","name":"lodash","version":"4.17.20"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"properties":{"method":{"const":"GET"},"queryParams":{"properties":{"ecosystem":{"description":"Package ecosystem: npm, pypi, go, maven, cargo, or nuget.","type":"string"},"name":{"description":"Package name (e.g. lodash, requests).","type":"string"},"version":{"description":"Version (defaults to latest).","type":"string"}},"required":["ecosystem","name"]},"type":{"const":"http"}},"required":["type","method","queryParams"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.0054,"price_match":true,"latency_ms":249,"error":null}],"description_full":"Security and provenance for an open-source package, composed live from three authoritative sources in one call. Pass ecosystem (npm, pypi, go, maven, cargo, nuget) + name (+ optional version; defaults to latest). Returns: known vulnerabilities from OSV (osv.dev — aggregates GitHub Security Advisories, PyPA, RustSec, Go vuln DB, etc.) each with its id, CVE aliases, summary, severity, and references; the resolved license and deprecation status (deps.dev); and the source repo's OpenSSF Scorecard health score (overall + per-check) plus stars/forks/open-issues. All live — newly-disclosed advisories appear within hours. Distinct from registry.npm-lookup / pypi-lookup (metadata only): this answers \"is this dependency safe to add, what license does it carry, and how well-maintained is it.\"","last_updated":"2026-09-19T15:57:14.836Z","schemes":["exact"]}