query_package
CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each OSV version range VERBATIM: events plus one render-safe projection: fixed (the upgrade targets) or affected_through (the last VULNERABLE version, so upgrade past it). This tool does not evaluate version membership; compare versions on your side with your ecosystem’s own semantics. Covers CVE-linked, GitHub-reviewed OSS advisories via OSV.dev; absence is not evidence of safety.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Package name, verbatim (for example @babel/core or org.jenkins-ci.main:jenkins-core) | |
| purl | No | Package URL, such as pkg:npm/lodash or pkg:maven/org.apache.logging.log4j/log4j-core | |
| ecosystem | No | OSV ecosystem (npm, PyPI, Maven, Go, crates.io, Packagist, RubyGems, NuGet, …) or purl type (pypi, cargo, composer, gem, golang, …) |