{"openapi":"3.1.0","info":{"title":"OSV Vulnerabilities","version":"1.0.0","description":"Open Source Vulnerability database: known CVEs and advisories for packages across npm, PyPI, crates.io, Go, and more. Machine-payable per request.","contact":{"email":"contact@meshgateway.co"},"x-guidance":"Every path is payable per request over HTTP 402 in USDG on eip155:4663. GET or POST without credentials to receive the challenge (WWW-Authenticate Payment header, plus the x402 payment-required header). Sign PermitWitnessTransferFrom for the advertised offer (spender is the canonical x402ExactPermit2Proxy) and retry with the payment-signature header. Buyers only need USDG: a one-time sponsored Permit2 approval is available at POST /api/gas/sponsor {\"address\"}."},"x-service-info":{"description":"Open Source Vulnerability database: known CVEs and advisories for packages across npm, PyPI, crates.io, Go, and more. Machine-payable per request."},"paths":{"/query":{"post":{"summary":"POST {\"package\":{\"name\":\"lodash\",\"ecosystem\":\"npm\"},\"version\":\"4.17.15\"} to list known vulnerabilities affecting that version.","requestBody":{"required":false,"content":{"application/json":{"schema":{"type":"object","additionalProperties":true,"description":"Forwarded to the upstream API verbatim"}}}},"responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.005000"},"protocols":[{"mpp":{"method":"evm","intent":"charge","currency":"0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168"}},{"x402":{}}],"amount":"5000","currency":"0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168","description":"OSV Vulnerabilities: Query by package","intent":"charge","method":"evm","recipient":"0xbB818E97E2260904B1D502E154488392ba2Ab5C9","scheme":"exact","network":"eip155:4663","extra":{"assetTransferMethod":"permit2","spender":"0x402085c248EeA27D92E8b30b2C58ed07f9E20001","name":"USDG"}}}},"/vuln":{"get":{"summary":"Append an OSV or GHSA id to the path, e.g. vuln/GHSA-jf85-cpcp-j695, for full advisory details.","responses":{"200":{"description":"Successful response"},"402":{"description":"Payment Required"}},"x-payment-info":{"price":{"mode":"fixed","currency":"USD","amount":"0.005000"},"protocols":[{"mpp":{"method":"evm","intent":"charge","currency":"0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168"}},{"x402":{}}],"amount":"5000","currency":"0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168","description":"OSV Vulnerabilities: Vulnerability by id","intent":"charge","method":"evm","recipient":"0xbB818E97E2260904B1D502E154488392ba2Ab5C9","scheme":"exact","network":"eip155:4663","extra":{"assetTransferMethod":"permit2","spender":"0x402085c248EeA27D92E8b30b2C58ed07f9E20001","name":"USDG"}}}}}}