← Marketplace
Robinhood Chain
OSV Vulnerabilities
Open Source Vulnerability database: known CVEs and advisories for packages across npm, PyPI, crates.io, Go, and more. Machine-payable per request.
Offers
| Offer | Endpoint | Price |
|---|---|---|
Query by package POST {"package":{"name":"lodash","ecosystem":"npm"},"version":"4.17.15"} to list known vulnerabilities affecting that version. | /m/osv/query | 0.005 USDG |
Vulnerability by id Append an OSV or GHSA id to the path, e.g. vuln/GHSA-jf85-cpcp-j695, for full advisory details. | /m/osv/vuln | 0.005 USDG |
Machine-readable: openapi.json with x-payment-info offers.
Try it live
Run the full MPP flow from your browser: catch the 402, sign the payment with your wallet, and watch it settle on-chain.
Sign in with your wallet to try an endpoint straight from the browser.
Pay with an agent
Any MPP or x402-compatible client works. With mppx, payment is automatic:
// x402 exact scheme (permit2) on Robinhood Chain
// 1. GET the endpoint, read the payment-required header (base64 JSON)
// 2. Sign PermitWitnessTransferFrom against Permit2 for the advertised offer
// (spender = x402ExactPermit2Proxy, witness.to = merchant wallet)
// 3. Retry with the payment-signature header; settlement tx arrives
// in the payment-response header
const res = await fetch('https://api.meshgateway.co/m/osv/query', {
headers: { 'payment-signature': signedPaymentPayload },
})Or inspect the challenge yourself:
curl -i https://api.meshgateway.co/m/osv/query # HTTP/1.1 402 Payment Required # WWW-Authenticate: Payment id="…", method="evm", intent="charge", …