deps.dev
Google's Open Source Insights: version history, licences, security advisories and source repositories for npm, PyPI, Go, Cargo, Maven, NuGet and RubyGems packages.
- Provider id:
depsdev - Tools: 2, at $0.001 per call
- Categories: Developer
- Homepage: deps.dev
- Provider docs: docs.deps.dev/api/v3
- Licence: CC BY 4.0
- Attribution: deps.dev (Open Source Insights, Google)
| Tool | Price | What it does |
|---|---|---|
depsdev/package | $0.001 | Any package's version history across npm, PyPI, Go, Cargo, Maven, NuGet, RubyGems, with its default version's licences and advisories. |
depsdev/version | $0.001 | One package version's licences, security advisories (OSV ids), links and source repository. |
Inputs are JSON bodies, and unknown fields are rejected with 422 invalid_input (not charged). POST /v1/inspect with a tool's id returns the same input schema, plus the output schema.
deps.dev Package
depsdev/package · $0.001 per call (local) · Developer
Any package's version history across npm, PyPI, Go, Cargo, Maven, NuGet, RubyGems, with its default version's licences and advisories.
One call per package in any of seven ecosystems: how many versions exist, which one is the default, when the first, newest and default versions were published, how many are deprecated, the five most recently published, and for the default version its SPDX licences, the OSV security advisories that affect it and its homepage/repository links. Data from Google's Open Source Insights (CC BY 4.0). For one specific version use depsdev/version; for npm download counts use npm/package.
Related: depsdev/version, npm/package, pypi/package, github/repo.
Input
| Field | Type | Required | Description |
|---|---|---|---|
system | string | yes | Package ecosystem: npm, pypi, go, cargo, maven, nuget or rubygems. One of npm, pypi, go, cargo, maven, nuget, rubygems. |
name | string | yes | Package name as the ecosystem spells it: 'express', 'requests', 'github.com/gin-gonic/gin', 'org.slf4j:slf4j-api'. 1–300 characters. |
Example
{
"system": "npm",
"name": "express"
}node akashi.mjs run depsdev/package --input '{"system":"npm","name":"express"}'deps.dev Package Version
depsdev/version · $0.001 per call (local) · Developer
One package version's licences, security advisories (OSV ids), links and source repository.
For an exact version of an npm, PyPI, Go, Cargo, Maven, NuGet or RubyGems package: its SPDX licences, the OSV advisory ids that affect it (e.g. GHSA-…), whether it is the default or deprecated, when it was published, its links and the source projects deps.dev relates it to, with how that relation is known. Good for 'is lodash 4.17.20 vulnerable' and licence checks. It does not resolve dependency trees; for the package's version list use depsdev/package.
Related: depsdev/package, npm/package, pypi/package, github/repo.
Input
| Field | Type | Required | Description |
|---|---|---|---|
system | string | yes | Package ecosystem: npm, pypi, go, cargo, maven, nuget or rubygems. One of npm, pypi, go, cargo, maven, nuget, rubygems. |
name | string | yes | Package name as the ecosystem spells it: 'express', 'requests', 'github.com/gin-gonic/gin', 'org.slf4j:slf4j-api'. 1–300 characters. |
version | string | yes | Exact version, e.g. '4.17.20'. 1–128 characters. |
Example
{
"system": "npm",
"name": "lodash",
"version": "4.17.20"
}node akashi.mjs run depsdev/version --input '{"system":"npm","name":"lodash","version":"4.17.20"}'