AkashiDocs
Providers

deps.dev

Google's Open Source Insights: version history, licences, security advisories and source repositories for npm, PyPI, Go, Cargo, Maven, NuGet and RubyGems packages.

  • Provider id: depsdev
  • Tools: 2, at $0.001 per call
  • Categories: Developer
  • Homepage: deps.dev
  • Provider docs: docs.deps.dev/api/v3
  • Licence: CC BY 4.0
  • Attribution: deps.dev (Open Source Insights, Google)
ToolPriceWhat it does
depsdev/package$0.001Any package's version history across npm, PyPI, Go, Cargo, Maven, NuGet, RubyGems, with its default version's licences and advisories.
depsdev/version$0.001One package version's licences, security advisories (OSV ids), links and source repository.

Inputs are JSON bodies, and unknown fields are rejected with 422 invalid_input (not charged). POST /v1/inspect with a tool's id returns the same input schema, plus the output schema.

deps.dev Package

depsdev/package · $0.001 per call (local) · Developer

Any package's version history across npm, PyPI, Go, Cargo, Maven, NuGet, RubyGems, with its default version's licences and advisories.

One call per package in any of seven ecosystems: how many versions exist, which one is the default, when the first, newest and default versions were published, how many are deprecated, the five most recently published, and for the default version its SPDX licences, the OSV security advisories that affect it and its homepage/repository links. Data from Google's Open Source Insights (CC BY 4.0). For one specific version use depsdev/version; for npm download counts use npm/package.

Related: depsdev/version, npm/package, pypi/package, github/repo.

Input

FieldTypeRequiredDescription
systemstringyesPackage ecosystem: npm, pypi, go, cargo, maven, nuget or rubygems. One of npm, pypi, go, cargo, maven, nuget, rubygems.
namestringyesPackage name as the ecosystem spells it: 'express', 'requests', 'github.com/gin-gonic/gin', 'org.slf4j:slf4j-api'. 1–300 characters.

Example

Input
{
  "system": "npm",
  "name": "express"
}
Run it with the CLI
node akashi.mjs run depsdev/package --input '{"system":"npm","name":"express"}'

deps.dev Package Version

depsdev/version · $0.001 per call (local) · Developer

One package version's licences, security advisories (OSV ids), links and source repository.

For an exact version of an npm, PyPI, Go, Cargo, Maven, NuGet or RubyGems package: its SPDX licences, the OSV advisory ids that affect it (e.g. GHSA-…), whether it is the default or deprecated, when it was published, its links and the source projects deps.dev relates it to, with how that relation is known. Good for 'is lodash 4.17.20 vulnerable' and licence checks. It does not resolve dependency trees; for the package's version list use depsdev/package.

Related: depsdev/package, npm/package, pypi/package, github/repo.

Input

FieldTypeRequiredDescription
systemstringyesPackage ecosystem: npm, pypi, go, cargo, maven, nuget or rubygems. One of npm, pypi, go, cargo, maven, nuget, rubygems.
namestringyesPackage name as the ecosystem spells it: 'express', 'requests', 'github.com/gin-gonic/gin', 'org.slf4j:slf4j-api'. 1–300 characters.
versionstringyesExact version, e.g. '4.17.20'. 1–128 characters.

Example

Input
{
  "system": "npm",
  "name": "lodash",
  "version": "4.17.20"
}
Run it with the CLI
node akashi.mjs run depsdev/version --input '{"system":"npm","name":"lodash","version":"4.17.20"}'

On this page