tools/osv/
Capability: contract:security-cross-ref
Kind: implementation
Vendor: OSV.dev
OSV.dev vulnerability cross-reference client.
Queries the OSV.dev REST API v1 for vulnerability records, aliases (CVE ↔ GHSA ↔ OSV IDs), affected package versions, and vulnerabilities associated with a public upstream commit.
Complements tools/cve-org/ and tools/cve-tool-vulnogram/ by providing cross-ecosystem vulnerability records for intended triage consumers (security-issue-triage, security-issue-deduplicate, security-cve-allocate, and dependency-audit — not yet wired).
See tool.md for endpoint recipes, payload structures, and confidentiality boundaries.
Prerequisites
- Runtime: Python 3.11+ via
uv(throughtools/vetted-opsdispatcher). - CLIs:
vetted-op-read(fromtools/vetted-ops) andjq. - Credentials / auth: None — open, unauthenticated REST API.
- Network:
api.osv.dev(REST API v1), routed throughvetted-opsHTTP read backend.
Configuration
Adopters select this backend with <project-config>/project.md → security_cross_ref.tool: osv when performing automated vulnerability cross-referencing.
The default ecosystem (e.g. PyPI, Maven, npm, Go, crates.io, NuGet, RubyGems, Packagist) can be configured via security_cross_ref.ecosystem.
The adopter-facing configuration block is declared in projects/_template/project.md.