OSV logo

OSV

OSV provides an open vulnerability database and API for querying vulnerabilities by package, version, commit, or vulnerability identifier.

5 actions Integration catalog
Request access
Connect OSV once you're in Boring.
01 · WHAT THE AGENT CAN DO

Actions

Every capability is a discrete, logged action the agent calls by name — scoped to what you authorize and recorded in the run trace.

Determine VersionOSV_DETERMINE_VERSION
Experimentally rank probable versions of an OSS-Fuzz C/C++ library from relative source-file paths and base64-encoded MD5 hashes. Results may be empty or change because the API is experimental.
Get Import FindingsOSV_GET_IMPORT_FINDINGS
Experimentally list OSV records from one exact import source that failed import-time quality checks; intended for OSV source maintainers and may return no records.
Get VulnerabilityOSV_GET_VULNERABILITY
Return the complete OSV record for one case-sensitive vulnerability ID, including affected versions, ranges, severity, references, and aliases.
Query VulnerabilitiesOSV_QUERY_VULNERABILITIES
Find full OSV vulnerability records affecting one package, package version, package URL, or commit. Use next_cursor to continue a large result set.
Query Vulnerabilities BatchOSV_QUERY_VULNERABILITIES_BATCH
Check up to 1,000 packages, package versions, package URLs, or commits in one request and return position-matched compact vulnerability IDs. Continue unfinished items with their individual page tokens.