Look up an ID
Paste a CVE, a GitHub GHSA, or another OSV id: PYSEC, GO, RUSTSEC, a Debian DSA, an Ubuntu USN. The record returns with a summary, a severity when the advisory includes one, the affected packages, and the references.
Open Source Vulnerabilities
Open Source Vulnerabilities is the MD Hub module for the public database at osv.dev. Look up a CVE or GHSA, query a package, or scan a lockfile. Use it with DGC Forge when a batch already calls open-source libraries, or when a move to another language brings new ones.
What it does
Paste a CVE, a GitHub GHSA, or another OSV id: PYSEC, GO, RUSTSEC, a Debian DSA, an Ubuntu USN. The record returns with a summary, a severity when the advisory includes one, the affected packages, and the references.
Choose an ecosystem, name the package, and add a version when you have one. Leave the version blank to list every known advisory for that name. A purl in the name field is accepted the same way.
Paste or upload composer.lock, package-lock.json, package.json, composer.json, requirements.txt, go.mod, Pipfile.lock, or a list of purls. The scan reads the packages in that file and asks osv.dev about them. The result stays on your account.
How it works
Open it from the backoffice under Open Source Vulnerabilities, or go to the app. Sign-in is required. Queries go to the public API at api.osv.dev.
ID lookup, Package, Scan lockfile, or History. A tutorial in the module walks those four jobs.
A lockfile is parsed on the server, then the packages are sent to api.osv.dev. One scan covers up to 400 packages. Each hit shows a severity of critical, high, medium, or low when the advisory carries a score.
Open a row for the summary, the affected version ranges, the version marked fixed when the advisory lists one, and the links it cites. History keeps earlier lookups on this account so you can open them again.
The same list is in the module. OSS-Fuzz is included there as well.
With DGC Forge
DGC Forge security checks read the batch you uploaded and land in the analysis column. Open Source Vulnerabilities reads published advisories for the packages that batch calls, and for the libraries a later language brings with it.
On an open project, use Analyze → Security checks. That report is about the source in the project. It stays in DGC Forge, next to identify, static analysis, efficiency, efficacy, suggested modernizations, and gap analysis.
When the batch already depends on open-source packages, collect the lockfile or manifest that names them. After GCL → other language, do the same for the target: Java and Maven, Python and requirements.txt, JavaScript or TypeScript and package-lock.json, Go and go.mod, PHP and composer.lock, and the other targets the forge can emit.
Open Open Source Vulnerabilities, choose Scan lockfile, and paste or upload the file. A CVE or GHSA named in a forge report can go straight into ID lookup. A single package and version can go into Package.
Affected ranges, a fixed version, and the cited references are what you take back when you accept a modernization or decide a dependency stays. Open the forge at legacy.md-hub.com and this module at osv.md-hub.com. Both use the same MD Hub sign-in.
Two reads, one account. A scan returns the advisories osv.dev currently publishes for those package versions. The forge security pass remains the read of the program. Run both before you trust a move to another language.