Data source
Data from OSV.dev (Google), delivered clean.
3 datasets pulled from OSV.dev (Google)'s releases, checked field by field and shipped the way you want them — daily, weekly, or hourly, your call.
- 3 datasets
- 1 industry
- Real rows on request
What Datadory delivers from OSV.dev (Google)
3OSV - Open Source Vulnerability Database
NVD CVE & CPE Data Feeds and APIs
deps.dev - Open Source Insights API
Pick a catch, see the rows.
Name any OSV.dev (Google) dataset and we send real rows from it — not a screenshot of rows. 1,744 datasets. Pick your catch.
Get a sampleAPI, files, or your warehouse. Daily, weekly, or hourly.
Straight answers about OSV.dev (Google) data
How many advisories does the OSV corpus hold?
848,582 across 38 package ecosystems as of 2026-08-21. npm leads at 226,498 - about 27 percent - with MinimOS at 127,499, GIT at 100,118, Debian at 63,701 and PyPI at 24,501 behind it. Depth varies by registry rather than averaging out, so scope requests per ecosystem when you request a sample.
What fields does each advisory record carry?
Twelve define the spine: an identifier, publication and modification stamps, a one-line summary, markdown detail, severity vectors, alias sets into CVE and PYSEC identifiers, typed references, and the affected array naming packages, version ranges and commits. A coarse severity bucket often rides in the extension object.
Does the data go down to package versions and commits?
Yes. Range objects arrive typed SEMVER, ECOSYSTEM or GIT, and their event markers separate introduced from fixed, last_affected and limit. Explicit affected-version lists accompany sources that can enumerate them, so a pinned dependency either falls inside the vulnerable window or it does not.
How far back does the advisory history run?
Sampled pulls show records from 2019 onward. Each carries a publication stamp fixing the original disclosure moment and a modification stamp advancing through every correction, plus a withdrawal marker where an advisory was retracted - five years of revision on a single flaw is common enough to plan around.