Skip to content

Eight ecosystems. Every source named.

Look up a package.

Check a single package against known advisories, and see its published versions, sizes and build provenance.

Parsed in your browser.

Your lockfile is never uploaded. Only package names and versions are sent, and anything resolving from a private registry is withheld.

Advisory data from the GitHub Advisory Database, PyPA, Go vulndb, RustSec and others via OSV.dev, cross-checked against deps.dev. Exploitation signals from CISA KEV. Individual sources and licences are shown on each finding.

PrivacyTerms