AcademyMCP serversDevelopment

osv-mcp, vulnerability queries for open source packages

Security and engineering teams that review dependencies and want known issues checked from an assistant.

  • Recommendedour rating
  • 42gitHub stars
  • Apache-2.0licence
  • 3 days agolast update
git clone https://github.com/StacklokLabs/osv-mcp.git
README.md

Loading the file...

What it does

An MCP server for the OSV open source vulnerability database. It checks a package version or commit for known vulnerabilities, runs batch queries across several packages and returns the details of a vulnerability by its ID. It is written in Go and runs over SSE.

Use cases

  1. 01Check a package version for known vulnerabilities
  2. 02Run one query for a list of dependencies
  3. 03Look up a vulnerability by its identifier

Questions about
osv-mcp, vulnerability queries for open source packages.

What is osv-mcp, vulnerability queries for open source packages used for?

Security and engineering teams that review dependencies and want known issues checked from an assistant. An MCP server for the OSV open source vulnerability database. It checks a package version or commit for known vulnerabilities, runs batch queries across several packages and returns the details of a vulnerability by its ID. It is written in Go and runs over SSE.

How do I install osv-mcp, vulnerability queries for open source packages?

Run this in your terminal: git clone https://github.com/StacklokLabs/osv-mcp.git

Is osv-mcp, vulnerability queries for open source packages open source?

Yes. The code is on GitHub (StacklokLabs/osv-mcp) under the Apache-2.0 licence.

Is osv-mcp, vulnerability queries for open source packages safe to use?

It passed our automatic scan for credential theft, hidden instructions and risky install commands. Third party open source software. Sabemos AI does not maintain it. Check the code and permissions before you connect it to company data.