OSV

by StacklokLabs

36 281 downloads Not rated yet MIT license

About

Access the [OSV (Open Source Vulnerabilities) database](https://osv.dev/) for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID.

Details

License
MIT license

Explore

- Query vulnerabilities by package name, ecosystem, and version or commit hash
- Batch query multiple packages or commits in a single call
- Get detailed information about a specific vulnerability by OSV ID
- Supports SSE and Streamable HTTP transport modes
- Configurable port and transport via environment variables
- Runs natively or via secure ToolHive container deployment

Prerequisites

- Go 1.21 or later
- Task (optional, for running tasks)
- ko (optional, for building container images)

The easiest way to run the OSV MCP server is using
ToolHive, which provides secure,
containerized deployment of MCP servers:

```bash

The server provides the following MCP tools:

Trust Score

An MCP (Model Context Protocol) server that provides access to the
OSV (Open Source Vulnerabilities) database.

Overview

This project implements an SSE-based MCP server that allows LLM-powered
applications to query the OSV database for vulnerability information. The server
provides tools for:

1. Querying vulnerabilities for a specific package version or commit
2. Batch querying vulnerabilities for multiple packages or commits
3. Getting detailed information about a specific vulnerability by ID

Installation

Prerequisites

- Go 1.21 or later
- Task (optional, for running tasks)
- ko (optional, for building container images)

Building from source

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.

Videos about OSV

Relevant YouTube tutorials, setups, and demos