osv-ecosystems
backlog row · status candidate · category SEC (Security advisories & identifiers) · lane B · refresh daily
What an agent uses it for
an agent pinning dependencies queries this for affected-version truth across Go/PyPI/npm, resolved to one record per vulnerability
Use it
xerj corpus add --from https://raw.githubusercontent.com/xerj-org/xerj/corpus-hub/tools/xerj-code/hub/osv-ecosystems.jsonxerj corpus index osv-ecosystems → xerj code osv-ecosystems "your question"Sources & pins
| source | pin | licence | size | review note |
|---|---|---|---|---|
| https://osv.dev | recipe | ? | curated pack | CC-BY-4.0 for OSV data (verify per ecosystem export) |
— across — · added —
Rights
? — see per-source review blocks . The review block records a human opening each licence file at the pin; detector output is a hint, never the verdict.
Retrieval spot-check (G7)
not yet spot-checked; queries are pre-registered in the registry before grading.