入门
在 Duaer 里查OSV 开源漏洞
在 Duaer 里:查询 OSV 中开源软件包或某版本的已知漏洞,覆盖 npm、PyPI、Go、Maven、crates.io 等生态,含严重程度与修复版本。一次成功查询用 1 额度。
能拿到什么
Duaer 数据市场里的「OSV 开源漏洞」:查询 OSV 中开源软件包或某版本的已知漏洞,覆盖 npm、PyPI、Go、Maven、crates.io 等生态,含严重程度与修复版本。查到结果时用 1 额度,结果交给数字组织的下一个节点。
从节点创建器选 Duaer 数据 → OSV 开源漏洞,或打开 数据市场。相关:NVD 漏洞库、npm 软件包。
适合做什么
- 检查某依赖的某个版本是否有已知漏洞。
- 查看漏洞影响的版本与修复版本。
在画布里检索
- 打开节点创建器,选 Duaer 数据 → OSV vulnerabilities。
- 填 Package(如 lodash);Ecosystem(如 npm)、Version 可选。或只填 Vulnerability ID。
- Limit 默认 10,最大 20。执行。
查到结果才扣 1 额度;没有结果、输入有误或上游失败都不扣。
用 API 调用
- GET https://api.duaer.com/v1/data/osv?package=lodash&version=4.17.15
- Authorization: Bearer <Duaer key>
下方是与数据市场「复制技能」相同的英文技能,含参数、示例与返回字段。
调用技能(英文)
与数据市场「复制技能」一致。
---
name: duaer-osv
description: >-
Duaer OSV vulnerabilities. Known vulnerabilities in an open-source package or version from OSV, across npm, PyPI, Go, Maven, crates.io, and more, with severity and fixed versions.
One successful search uses 1 Duaer credit.
---
# Duaer OSV vulnerabilities
Duaer OSV vulnerabilities queries the OSV database that aggregates GitHub advisories, PyPA, Go, RustSec, and other feeds. Give a package, optionally a version, or one vulnerability id.
## When to use
- Check whether a dependency version has known vulnerabilities.
- Find the version that fixes an advisory.
## When not to use
- CVSS details for one CVE. Use https://skills.duaer.com/nvd.md.
- Vulnerabilities attacked in the wild. Use https://skills.duaer.com/cisa-kev.md.
## Call
`GET https://api.duaer.com/v1/data/osv?package=lodash&version=4.17.15`
Header: `Authorization: Bearer <Duaer key>`
Use an account key or a model API key.
Get a Duaer key: https://skills.duaer.com/keys.md
## Parameters
Provide `package`, or `id`.
- `package` — Package name, such as lodash or requests.
- `ecosystem` — Optional. npm, PyPI, Go, Maven, crates.io, NuGet, RubyGems, Packagist, Pub, Hex, Hackage, SwiftURL, Debian, Alpine, or Ubuntu. Default npm.
- `version` — Optional. Only vulnerabilities that affect this version.
- `id` — Optional. One entry such as GHSA-29mw-wpgm-hmr9 or CVE-2021-44228.
- `limit` — Optional. Rows to return, from 1 to 20. Default 10.
## Examples
- `GET https://api.duaer.com/v1/data/osv?package=lodash&version=4.17.15` — vulnerabilities in lodash 4.17.15.
- `GET https://api.duaer.com/v1/data/osv?package=django&ecosystem=PyPI&limit=5` — recent Django advisories.
## Result
The response is `{ "items": [...] }`. Each item has `source`, `title`, `url`, and `summary`, plus:
- `vulnerabilityId`, `aliases` — OSV id and CVE or GHSA aliases.
- `severity`, `cvss`, `cwe` — severity label, CVSS vector, and weakness ids.
- `fixedVersions` — versions that fix it for this package.
- `published`, `modified` — dates.
Rows are newest first.
Fields without a value are left out.
## Credits
A search that returns at least one row uses 1 credit.
An empty search, a search that finds nothing, or a failed search uses 0.
Wrong input returns 400 with a message and uses 0.
No remaining credits returns 402 and does not search.
A missing key returns 401.
## Related
- https://skills.duaer.com/nvd.md — Duaer NVD CVE records
- https://skills.duaer.com/npm.md — Duaer npm packages
常见问题
Duaer 的OSV 开源漏洞检索扣多少额度?
查到结果时扣 1 额度;没有结果或出错不扣。
Duaer OSV 开源漏洞需要填版本吗?
不必。在 Duaer 里不填 Version 会列出该包的全部已知漏洞;填了只返回影响该版本的漏洞。
同组