# Open Source Dependency Vulnerability Scanner (`scrapemint/dependency-vulnerability-scanner`) Actor

Scan dependencies against the OSV.dev database. Supply packages as ecosystem:name@version (npm, PyPI, Go, Maven, crates.io and more); get one row per known vulnerability with OSV/GHSA id, CVE aliases, severity, affected range, and the fix version. Dedupe mode gives a new-vulnerability feed.

- **URL**: https://apify.com/scrapemint/dependency-vulnerability-scanner.md
- **Developed by:** [Ken M](https://apify.com/scrapemint) (community)
- **Categories:** Developer tools, Business
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: 5.00 out of 5 stars

## Pricing

Pay per usage

This Actor is paid per platform usage. The Actor is free to use, and you only pay for the Apify platform usage, which gets cheaper the higher subscription plan you have.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-usage

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## Open Source Dependency Vulnerability Scanner

Scan your software dependencies against **[OSV.dev](https://osv.dev)** — Google's Open Source Vulnerabilities database, which aggregates GitHub Security Advisories, PyPA, RustSec, the Go vulnerability database, npm and many more into one schema. Supply a list of packages and get **one row per known vulnerability**: the OSV/GHSA id, CVE aliases, severity, CWEs, the affected version range, and the version that fixes it.

No API key, no account. Packages with no known vulnerabilities produce no rows and cost nothing — so scanning a clean tree is effectively free. Turn on **dedupe** with a schedule to be alerted only when a *new* vulnerability starts affecting something you ship.

### Who uses it

- **Engineering & DevSecOps** — a scheduled check over the dependencies you ship, without wiring a scanner into every repo.
- **Security teams / MSPs** — audit a client's stack from a plain package list (SBOM export, `package-lock.json`, `requirements.txt`, `go.mod`).
- **Procurement & due diligence** — check a vendor's declared dependencies before you sign.

Pairs with the **CVE Vulnerability Tracker** (which discovers CVEs by vendor/product across NVD) — this actor answers the complementary question: *do my exact versions have known issues, and what do I upgrade to?*

### Input

Provide `packages` as `ecosystem:name@version` entries:

```
npm:lodash@4.17.15
PyPI:django@3.2.0
Go:github.com/gin-gonic/gin@1.6.0
Maven:com.fasterxml.jackson.core:jackson-databind@2.9.8
crates.io:openssl@0.10.0
```

- Omit `@version` to get **all** known vulnerabilities for a package.
- The `ecosystem:` prefix is optional if you set a **default ecosystem**.
- Supported ecosystems: npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex and more. Common aliases (`pip`, `cargo`, `gem`, `golang`, …) are accepted.

| Field | Description |
|-------|-------------|
| `packages` | Dependency list, one `ecosystem:name@version` per entry. |
| `ecosystem` | Default ecosystem for entries with no prefix. |
| `severityMin` | Keep only `low`/`moderate`/`high`/`critical` and above. Unrated vulns are always kept. |
| `includeCleanRows` | Also emit a row for packages with no vulnerabilities. Off by default. |
| `maxRows` | Cap on rows per run. |
| `dedupe` | Remember package+vulnerability pairs across runs; only return new ones. Use with a schedule. |

### Output

One row per vulnerability: `package`, `ecosystem`, `queriedVersion`, `vulnId`, `aliases`, `cve`, `severity`, `cvssVector`, `cwe`, `summary`, `firstPatchedVersion`, `fixedVersions`, `introducedVersions`, `references`, `published`, `modified`, `url`.

### Pricing

Pay per event: **$0.004 per vulnerability row**. Clean packages cost nothing. The first 2 rows of every run are free.

Data source: [OSV.dev](https://osv.dev) (open data, CC-BY-4.0).

# Actor input Schema

## `packages` (type: `array`):

One entry per dependency as ecosystem:name@version, e.g. npm:lodash@4.17.15, PyPI:django@3.2.0, Go:github.com/gin-gonic/gin@1.6.0, Maven:com.fasterxml.jackson.core:jackson-databind@2.9.8. Omit @version to get all known vulnerabilities for the package. The ecosystem prefix is optional if you set a default ecosystem below.

## `ecosystem` (type: `string`):

Used for entries with no ecosystem prefix. Accepts npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex (common aliases like pip, cargo, gem also work).

## `severityMin` (type: `string`):

Keep only vulnerabilities at or above this severity. Vulnerabilities with no published severity are always kept.

## `includeCleanRows` (type: `boolean`):

Also emit one row per package that has no known vulnerabilities (vulnerable=false). Off by default so clean packages cost nothing.

## `maxRows` (type: `integer`):

Cap on rows returned. Controls total cost.

## `dedupe` (type: `boolean`):

Remember returned package+vulnerability pairs across runs and skip them. Turn on with a schedule to get alerted only when a NEW vulnerability affects your dependency set.

## Actor input object example

```json
{
  "packages": [
    "npm:lodash@4.17.15",
    "PyPI:django@3.2.0",
    "npm:express@4.17.1"
  ],
  "ecosystem": "",
  "severityMin": "any",
  "includeCleanRows": false,
  "maxRows": 1000,
  "dedupe": false
}
```

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "packages": [
        "npm:lodash@4.17.15",
        "PyPI:django@3.2.0",
        "npm:express@4.17.1"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("scrapemint/dependency-vulnerability-scanner").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "packages": [
        "npm:lodash@4.17.15",
        "PyPI:django@3.2.0",
        "npm:express@4.17.1",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("scrapemint/dependency-vulnerability-scanner").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "packages": [
    "npm:lodash@4.17.15",
    "PyPI:django@3.2.0",
    "npm:express@4.17.1"
  ]
}' |
apify call scrapemint/dependency-vulnerability-scanner --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=scrapemint/dependency-vulnerability-scanner",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/acts/w2ZAN3s8y1ZfOyynl/builds/WKspl5gbDMlcZ9LS4/openapi.json
