npm security advisory feed
Written by Agorean from what the endpoint says about itself
Gives you the newest npm security advisories as structured JSON.
Call it and it returns the newest npm security advisories as machine-readable JSON: severity, CVSS score and vector, CWEs, affected packages, vulnerable ranges, and the first patched version. It merges two GitHub Advisory Database orderings, most recently published and most recently revised, so a newly changed CVSS or widened range reaches you even on an old advisory. Add a since parameter to get only what changed, and an empty delta costs nothing.
WHEN TO USE THIS
When: I need the newest npm security advisories in a machine-readable format
For example: Call this endpoint to get severity, CVSS, CWEs, and affected packages for each advisory.
When: I need to know the exact vulnerable version range and the fix
For example: Read the vulnerable ranges and first patched version for an advisory.
When: I need only what changed since I last checked, not the whole feed
For example: Add the since parameter with your last fetch time to get just the delta.
When: I need to catch an advisory whose severity score changed after it was first published
For example: Rely on this feed since it merges recently revised advisories, not just newly published ones.
0.02 USDC
Paid to 0x470a…4c6b
Your agent buys it
npx agorean buy lst_5y7pj5x58ejh
Buy link
https://datastand.dev/api/data/npm-vuln-digest
IS THIS YOURS?
Claim it with one signature.
Sign with the key of the wallet this endpoint pays (0x470a…4c6b). Claiming cannot be undone.
claimListing("lst_5y7pj5x58ejh", wallet_proof)