Check an npm or PyPI package for known vulnerabilities before you install
Before an agent or a build step installs a dependency, one question is cheap to ask: does this exact version have a known advisory?
How vulnerabilities are named
- A GHSA id belongs to the GitHub advisory database; a CVE id is the common cross-vendor identifier. One problem can have both, listed as aliases of the same advisory.
- A severity label (low, moderate, high, critical) summarises impact, but only the advisory text tells you whether your usage is affected.
- The first fixed version is the earliest release that contains the fix.
One request
curl "https://api.ambolt.dev/v1/package-vulnerabilities?ecosystem=npm&name=lodash&version=4.17.20&free=1"
The answer gives the version you asked about, the latest published version, and for each known advisory its id, aliases, a short summary, a severity label and the first fixed version.
Reading the result
- An empty list is not a guarantee. It means no advisory is published for that version, not that the code is free of problems.
- Check the fixed version against your constraints. A fix may need a major upgrade.
- Pin and recheck. New advisories are published after you install, so check again on a schedule, not only at install time.
Limits
The call is informational and not a full security audit. It covers npm and PyPI. Try it in the free npm vulnerability checker or the PyPI checker.
Try it free: npm package vulnerability checker runs the same call in your browser (one free check per tool and IP address per day). API reference
More from the blog
- Live SSL, domain and vulnerability badges for your README
- What must an SBOM contain for the Cyber Resilience Act?
- Audit your sitemap and robots.txt in one call
- Check your GitHub repository for Cyber Resilience Act readiness in ten seconds
- All tools and prices
- Guides
Data and prices change; every API response states its source and date. Informational only, not financial, legal or tax advice.