{"slug":"audit-152-53-82-29-sslip-io-v1-vulns-2689e9","title":"Known vulnerabilities for a list of dependencies, npm and PyPI, in one call","host":"audit.152-53-82-29.sslip.io","method":"POST","resource":"https://audit.152-53-82-29.sslip.io/v1/vulns","category":"code","description":"Known vulnerabilities for a list of dependencies, npm and PyPI, in one call. Send {\"npm\":[\"lodash@4.17.20\"],\"pypi\":[\"django==3.2.0\"]} or a package.json or requirements.txt, up to 50 packages. Returns only packages that have advisories: OSV and GHSA ids, CVE aliases, severity, summary, and the first ","price_listed":0.005,"price_asked":null,"state":"effects","state_label":"Not tested: has real-world effects","checks_7d":0,"answered_7d":0,"latency_ms_median":null,"reported_calls_30d":2,"reported_payers_30d":1,"networks":["eip155:137","eip155:8453","solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"npm":["lodash@4.17.20"],"pypi":["django==3.2.0"]},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"properties":{"ecosystem":{"enum":["npm","pypi"],"type":"string"},"manifest":{"type":"string"},"npm":{"items":{"type":"string"},"type":"array"},"pypi":{"items":{"type":"string"},"type":"array"}},"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"properties":{"elapsed_ms":{"type":"integer"},"rows":{"items":{"properties":{"ecosystem":{"type":"string"},"max_severity":{"type":["string","null"]},"name":{"type":"string"},"version_checked":{"type":["string","null"]},"vulnerabilities":{"items":{"properties":{"aliases":{"items":{"type":"string"},"type":"array"},"fixed_in":{"type":["string","null"]},"id":{"type":"string"},"severity":{"type":"string"},"summary":{"type":"string"}},"type":"object"},"type":"array"},"vulnerability_count":{"type":"integer"}},"type":"object"},"type":"array"},"sources":{"items":{"type":"string"},"type":"array"},"summary":{"properties":{"max_severity":{"type":["string","null"]},"packages":{"type":"integer"},"total_vulnerabilities":{"type":"integer"},"with_vulnerabilities":{"type":"integer"}},"type":"object"}},"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[],"description_full":"Known vulnerabilities for a list of dependencies, npm and PyPI, in one call. Send {\"npm\":[\"lodash@4.17.20\"],\"pypi\":[\"django==3.2.0\"]} or a package.json or requirements.txt, up to 50 packages. Returns only packages that have advisories: OSV and GHSA ids, CVE aliases, severity, summary, and the first fixed version, plus counts. Unpinned packages are checked at their latest version. Deterministic OSV data, no LLM.","last_updated":"2026-09-23T14:02:02.722Z","schemes":["exact"]}