Audit a whole lockfile for known vulnerabilities and malware in one call
Audit a whole lockfile for known vulnerabilities and malware in one call: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, uv.lock, Pipfile.lock, Cargo.lock or go.sum, up to 1,000 exact versions checked against OSV.dev, with affected packages, severity and versions to upgrade to. POST {url} (raw file) or {content, filename}.
Answeringour last check, 2026-09-29
1 of 1checks answered this week
46 msmedian answer time
$0.05listed price per call
$0.05price it asked us
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://aayatai.com/package/audit/lockfile
| Category | Code and developer |
|---|---|
| Provider host | aayatai.com |
| Networks | eip155:137, eip155:42161, eip155:8453, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-09-29 | valid payment request | 402 | $0.05 | 46 ms |
Example input (from the provider)
{
"body": {
"content": "requests==2.19.0\nurllib3==1.26.18\n",
"filename": "requirements.txt"
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"properties": {
"content": {
"description": "Or: the lockfile text itself (up to 60 KB; use url for bigger files).",
"maxLength": 60000,
"type": "string"
},
"filename": {
"description": "The file's name when sending content, e.g. poetry.lock (helps detect the format).",
"maxLength": 100,
"type": "string"
},
"format": {
"description": "Force the format if detection fails.",
"enum": [
"package-lock",
"yarn",
"pnpm",
"requirements",
"poetry",
"uv",
"pipfile",
"cargo",
"gosum"
],
"type": "string"
},
"url": {
"description": "Raw lockfile address, e.g. https://raw.githubusercontent.com/owner/repo/main/package-lock.json.",
"format": "uri",
"maxLength": 2048,
"type": "string"
}
},
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"properties": {
"checked": {
"type": "integer"
},
"checkedAt": {
"type": "string"
},
"cleanCount": {
"type": "integer"
},
"counts": {
"type": "object"
},
"detailsTruncated": {
"type": "boolean"
},
"ecosystem": {
"type": "string"
},
"format": {
"enum": [
"package-lock",
"yarn",
"pnpm",
"requirements",
"poetry",
"uv",
"pipfile",
"cargo",
"gosum"
],
"type": "string"
},
"found": {
"description": "Exact package versions found in the file.",
"type": "integer"
},
"packages": {
"description": "Affected packages with vulnerabilities and upgradeTo.",
"items": {
"type": "object"
},
"type": "array"
},
"source": {
"description": "url or content.",
"type": "string"
},
"truncated": {
"description": "True if the file had more than 1000 packages (the first 1000 were checked).",
"type": "boolean"
},
"verdict": {
"enum": [
"clean",
"review",
"fix",
"malware"
],
"type": "string"
},
"vulnerablePackages": {
"type": "integer"
}
},
"required": [
"format",
"ecosystem",
"found",
"checked",
"verdict",
"packages"
],
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}