{"api":"v1","generated_at":"2026-09-15T18:51:21.398Z","licence":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/","attribution":"TOLL, with a link to the page cited"},"page":"https://tollindex.com/e/dependency-risk-use-x402atlas-com-batch-1871e8","pinned_page":"https://tollindex.com/e/dependency-risk-use-x402atlas-com-batch-1871e8/at/2026-09-15T16-57Z","pinned":false,"method":"https://tollindex.com/ledger/method","snapshot_at":"2026-09-15T16:57:44.360Z","snapshot_stamp":"2026-09-15T16-57Z","endpoint":{"slug":"dependency-risk-use-x402atlas-com-batch-1871e8","canonical_url":"https://dependency-risk.use.x402atlas.com/batch","resource":"https://dependency-risk.use.x402atlas.com/batch","http_method":"POST","type":"http","x402_version":2,"registries":["cdp"],"primary_registry":"cdp","curated_by_coinbase":false,"description":"Batch dependency vulnerability check — check ordered exact package versions in OSV with deduplicated CVE enrichment, explicit completeness, and CISA KEV known-exploited signals.","service_name":"Open Source Vulnerability Check","declared_category":"security","declared_tags":["batch-vulnerability-check","osv","cve","cisa-kev","software-supply-chain"],"route_template":null,"registry_updated":"2026-09-15T06:32:24.704Z"},"derived":{"note":"fields no registry supplies; TOLL derives them and marks them derived on the page","title":"batch","category":"market-data","first_observed_by_toll":"2026-09-10T19:08:24.178Z","last_observed_by_toll":"2026-09-15T16:57:44.360Z","observation_began":"2026-09-10"},"presence":{"listed_now":true,"first_absent_at":null,"delisting_confirmed_at":null,"events":[{"registry":"cdp","at":"2026-09-10T19:08:24.178Z","event":"listed"}]},"accepts":[{"registry":"cdp","ordinal":0,"network":"eip155:8453","asset":"0x833589fcd6edb6e08f4c7c32d4f71b54bda02913","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.01 USDC","amount_units":0.01,"decimals_known":true,"pay_to":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","scheme":"exact"},{"registry":"cdp","ordinal":1,"network":"eip155:137","asset":"0x3c499c542cef5e3811e1192ce70d8cc03d5c3359","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.01 USDC","amount_units":0.01,"decimals_known":true,"pay_to":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","scheme":"exact"},{"registry":"cdp","ordinal":2,"network":"eip155:42161","asset":"0xaf88d065e77c8cc2239327c5edb3a432268e5831","asset_name":"USD Coin","symbol":"USDC","decimals":6,"amount_display":"0.01 USDC","amount_units":0.01,"decimals_known":true,"pay_to":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","scheme":"exact"}],"counters":{"observed_at":"2026-09-15T16:57:44.360Z","calls_30d":3,"unique_payers_30d":2,"last_called_at":"2026-09-15T06:32:21.336Z"},"validation":{"latest":{"observed_at":"2026-09-15T04:04:27.354Z","state":"pass","failed_checks":[],"endpoint_http_status":402,"run_id":"daily-2026-09-15"},"uptime":[{"days":7,"observed":5,"passed":5,"ratio":1},{"days":30,"observed":5,"passed":5,"ratio":1},{"days":90,"observed":5,"passed":5,"ratio":1}],"history_90d":[{"observed_at":"2026-09-15T04:04:27.354Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-15","state_changed":false},{"observed_at":"2026-09-14T04:03:07.297Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-14","state_changed":false},{"observed_at":"2026-09-13T04:02:45.489Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-13","state_changed":false},{"observed_at":"2026-09-12T06:17:52.617Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-12","state_changed":false},{"observed_at":"2026-09-11T09:44:05.897Z","state":"pass","failed_checks":[],"run_id":"daily-2026-09-11","state_changed":true}]},"seller":{"wallet":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","page":"https://tollindex.com/seller/0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","endpoints":62,"hosts":18},"reports":0,"registry_record":{"cdp":[{"tags":["batch-vulnerability-check","osv","cve","cisa-kev","software-supply-chain"],"type":"http","accepts":[{"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"name":"USD Coin","tier":"standard","version":"2","merchant":"x402Atlas"},"payTo":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","amount":"10000","scheme":"exact","network":"eip155:8453","maxTimeoutSeconds":300},{"asset":"0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359","extra":{"name":"USD Coin","tier":"standard","version":"2","merchant":"x402Atlas"},"payTo":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","amount":"10000","scheme":"exact","network":"eip155:137","maxTimeoutSeconds":300},{"asset":"0xaf88d065e77c8cC2239327C5EDb3A432268e5831","extra":{"name":"USD Coin","tier":"standard","version":"2","merchant":"x402Atlas"},"payTo":"0x8C128f1Ee62Bb5e47867CfbAe2ad89be325Df1b2","amount":"10000","scheme":"exact","network":"eip155:42161","maxTimeoutSeconds":300}],"quality":{"lastCalledAt":"2026-09-15T06:32:21.336Z","l30DaysTotalCalls":3,"l30DaysUniquePayers":2},"resource":"https://dependency-risk.use.x402atlas.com/batch","extensions":{"bazaar":{"info":{"input":{"body":{"packages":[{"purl":"pkg:golang/golang.org/x/text@v0.3.7"},{"purl":"pkg:golang/golang.org/x/text@v0.3.7"}]},"type":"http","method":"POST","bodyType":"json"},"output":{"type":"json","example":{"stale":false,"source":{"osv":{"name":"OSV.dev"},"cisa_kev":{"name":"Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog","retrieved_at":"2026-08-02T00:00:00Z","date_released":"2026-07-29T18:45:59.5809Z","catalog_version":"2026.07.29"}},"partial":false,"results":[{"input":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.3.7","version":"v0.3.7","ecosystem":"golang"},"status":"vulnerabilities_found","summary":{"kev_count":0,"max_severity":"high","finding_count":3},"findings":[{"id":"GHSA-69ch-w2m2-3vjp","aliases":["CVE-2022-32149","GO-2022-1059"],"summary":"golang.org/x/text/language Denial of service via crafted Accept-Language header","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.8"}]}],"package":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text","ecosystem":"Go"},"severity":[],"versions":[]}],"modified":"2026-02-04T03:11:34.199431Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"published":"2022-10-14T19:00:40Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32149","type":"ADVISORY"},{"url":"https://github.com/golang/go/issues/56152","type":"WEB"},{"url":"https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c","type":"WEB"},{"url":"https://github.com/golang/text","type":"PACKAGE"},{"url":"https://go.dev/cl/442235","type":"WEB"},{"url":"https://go.dev/issue/56152","type":"WEB"},{"url":"https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ","type":"WEB"},{"url":"https://pkg.go.dev/vuln/GO-2022-1059","type":"WEB"},{"url":"https://security.netapp.com/advisory/ntap-20230203-0006","type":"WEB"}],"max_severity":"high","fixed_versions":["0.3.8"]},{"id":"GO-2022-1059","aliases":["CVE-2022-32149","GHSA-69ch-w2m2-3vjp"],"summary":"Denial of service via crafted Accept-Language header in golang.org/x/text/language","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.8"}]}],"package":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text","ecosystem":"Go"},"severity":[],"versions":[]}],"modified":"2026-02-04T03:39:03.311488Z","severity":[],"published":"2022-10-11T18:16:24Z","withdrawn":false,"references":[{"url":"https://go.dev/issue/56152","type":"REPORT"},{"url":"https://go.dev/cl/442235","type":"FIX"},{"url":"https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ","type":"WEB"}],"max_severity":"unknown","fixed_versions":["0.3.8"]},{"id":"GO-2026-5970","aliases":["CVE-2026-56852"],"summary":"Infinite loop on invalid input in golang.org/x/text","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.39.0"}]}],"package":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text","ecosystem":"Go"},"severity":[],"versions":[]}],"modified":"2026-07-22T20:59:36.034292423Z","severity":[],"published":"2026-07-14T17:29:56Z","withdrawn":false,"references":[{"url":"https://go.dev/issue/80142","type":"REPORT"},{"url":"https://go.dev/cl/794100","type":"FIX"}],"max_severity":"unknown","fixed_versions":["0.39.0"]}]},{"input":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.3.7","version":"v0.3.7","ecosystem":"golang"},"status":"vulnerabilities_found","summary":{"kev_count":0,"max_severity":"high","finding_count":3},"findings":[{"id":"GHSA-69ch-w2m2-3vjp","aliases":["CVE-2022-32149","GO-2022-1059"],"summary":"golang.org/x/text/language Denial of service via crafted Accept-Language header","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.8"}]}],"package":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text","ecosystem":"Go"},"severity":[],"versions":[]}],"modified":"2026-02-04T03:11:34.199431Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"published":"2022-10-14T19:00:40Z","withdrawn":false,"references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32149","type":"ADVISORY"},{"url":"https://github.com/golang/go/issues/56152","type":"WEB"},{"url":"https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c","type":"WEB"},{"url":"https://github.com/golang/text","type":"PACKAGE"},{"url":"https://go.dev/cl/442235","type":"WEB"},{"url":"https://go.dev/issue/56152","type":"WEB"},{"url":"https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ","type":"WEB"},{"url":"https://pkg.go.dev/vuln/GO-2022-1059","type":"WEB"},{"url":"https://security.netapp.com/advisory/ntap-20230203-0006","type":"WEB"}],"max_severity":"high","fixed_versions":["0.3.8"]},{"id":"GO-2022-1059","aliases":["CVE-2022-32149","GHSA-69ch-w2m2-3vjp"],"summary":"Denial of service via crafted Accept-Language header in golang.org/x/text/language","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.8"}]}],"package":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text","ecosystem":"Go"},"severity":[],"versions":[]}],"modified":"2026-02-04T03:39:03.311488Z","severity":[],"published":"2022-10-11T18:16:24Z","withdrawn":false,"references":[{"url":"https://go.dev/issue/56152","type":"REPORT"},{"url":"https://go.dev/cl/442235","type":"FIX"},{"url":"https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ","type":"WEB"}],"max_severity":"unknown","fixed_versions":["0.3.8"]},{"id":"GO-2026-5970","aliases":["CVE-2026-56852"],"summary":"Infinite loop on invalid input in golang.org/x/text","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.39.0"}]}],"package":{"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text","ecosystem":"Go"},"severity":[],"versions":[]}],"modified":"2026-07-22T20:59:36.034292423Z","severity":[],"published":"2026-07-14T17:29:56Z","withdrawn":false,"references":[{"url":"https://go.dev/issue/80142","type":"REPORT"},{"url":"https://go.dev/cl/794100","type":"FIX"}],"max_severity":"unknown","fixed_versions":["0.39.0"]}]}],"warnings":[],"operation":"batch-check","retrieved_at":"2026-08-02T00:00:00Z","schema_version":"dependency-risk-v1"}}},"tags":["batch-vulnerability-check","osv","cve","cisa-kev","software-supply-chain"],"schema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object","required":["packages"],"properties":{"packages":{"type":"array","items":{"type":"object","oneOf":[{"not":{"anyOf":[{"required":["package"]},{"required":["version"]}]},"required":["purl"]},{"not":{"required":["purl"]},"required":["package","version"]}],"properties":{"purl":{"type":"string","maxLength":2048,"minLength":1,"description":"Canonical package URL with embedded exact version; mutually exclusive with package and version"},"package":{"type":"object","required":["ecosystem","name"],"properties":{"name":{"type":"string","maxLength":512,"minLength":1,"description":"Exact package-manager name, up to 512 UTF-8 bytes"},"ecosystem":{"type":"string","maxLength":64,"minLength":1,"description":"Exact OSV ecosystem identifier, up to 64 UTF-8 bytes"}},"description":"Exact OSV package identity; use with version","additionalProperties":false},"version":{"type":"string","maxLength":256,"minLength":1,"description":"Exact version used with package, up to 256 UTF-8 bytes"}},"description":"One exact package version using exactly one accepted identifier form","additionalProperties":false},"maxItems":50,"minItems":1,"description":"Ordered exact package versions; duplicates preserve positions and share source work. The complete OSV result must contain no page token and at most eight distinct vulnerability IDs for V1 enrichment."}},"additionalProperties":false},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["operation","schema_version","source","retrieved_at","stale","warnings","results","partial"],"properties":{"stale":{"type":"boolean","description":"True only when a prior validated CISA KEV snapshot is served after refresh failure; OSV result completeness is never silently marked stale"},"_atlas":{"type":"object","required":["docs"],"properties":{"docs":{"type":"string","format":"uri","maxLength":512,"description":"Documentation URL for this bridge"},"related":{"type":"array","items":{"type":"object","required":["bridge","url","docs","summary"],"properties":{"url":{"type":"string","format":"uri","maxLength":512,"description":"Related route URL"},"docs":{"type":"string","format":"uri","maxLength":512,"description":"Related bridge documentation URL"},"bridge":{"type":"string","maxLength":64,"description":"Related bridge name"},"summary":{"type":"string","maxLength":256,"description":"Short capability summary"}},"description":"One related Atlas route","additionalProperties":false},"maxItems":3,"description":"Bounded related Atlas routes"}},"description":"Atlas documentation and related-route metadata added after deployment","additionalProperties":false},"source":{"type":"object","required":["osv","cisa_kev"],"properties":{"osv":{"type":"object","required":["name"],"properties":{"name":{"type":"string","const":"OSV.dev","description":"Official OSV.dev vulnerability record aggregator"}},"description":"OSV source identity; individual finding times carry record publication and modification semantics","additionalProperties":false},"cisa_kev":{"type":"object","required":["name","catalog_version","date_released","retrieved_at"],"properties":{"name":{"type":"string","const":"Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog","description":"Official CISA KEV source name"},"retrieved_at":{"type":"string","format":"date-time","description":"UTC time this exact validated KEV snapshot was retrieved"},"date_released":{"type":"string","description":"Release time published in the validated CISA feed"},"catalog_version":{"type":"string","description":"Catalog version published in the validated CISA feed"}},"description":"Validated CISA Known Exploited Vulnerabilities snapshot used for exact CVE enrichment","additionalProperties":false}},"description":"Named public sources and the exact CISA KEV snapshot used for this response","additionalProperties":false},"partial":{"type":"boolean","description":"True only when at least one complete item succeeded and another detail lookup transiently failed"},"results":{"type":"array","items":{"type":"object","oneOf":[{"not":{"required":["error_code"]},"required":["summary"],"properties":{"status":{"enum":["no_known_vulnerabilities","vulnerabilities_found"],"description":"A complete named-source conclusion requires summary and omits error_code"}}},{"not":{"required":["summary"]},"required":["error_code"],"properties":{"status":{"const":"query_failed","description":"An incomplete upstream result requires error_code and omits summary so it cannot resemble a risk conclusion"}}}],"required":["input","status","findings"],"properties":{"input":{"type":"object","required":["ecosystem","name","version"],"properties":{"name":{"type":"string","description":"Exact package-manager name"},"purl":{"type":"string","description":"Canonical input purl when the caller used purl form; otherwise omitted"},"version":{"type":"string","description":"Exact queried package version"},"ecosystem":{"type":"string","description":"Exact package ecosystem; purl types remain canonical lowercase identifiers"}},"description":"Canonical exact package/version identity","additionalProperties":false},"status":{"enum":["no_known_vulnerabilities","vulnerabilities_found","query_failed"],"type":"string","description":"Named-source conclusion: query_failed is explicit incompleteness and never a clean result"},"summary":{"type":"object","required":["finding_count","kev_count","max_severity"],"properties":{"kev_count":{"type":"integer","maximum":8,"minimum":0,"description":"Active findings with an exact KEV CVE match"},"max_severity":{"enum":["unknown","low","medium","high","critical"],"type":"string","description":"Highest parseable published CVSS severity among active findings"},"finding_count":{"type":"integer","maximum":8,"minimum":0,"description":"Active non-withdrawn finding count"}},"description":"Summary of active non-withdrawn findings","additionalProperties":false},"findings":{"type":"array","items":{"type":"object","required":["id","aliases","modified","withdrawn","affected","references","severity","max_severity","fixed_versions"],"properties":{"id":{"type":"string","description":"Authoritative OSV record identifier"},"kev":{"type":"object","required":["cve_id","vendor_project","product","vulnerability_name","date_added","short_description","required_action","due_date","cwes"],"properties":{"cwes":{"type":"array","items":{"type":"string"},"description":"CWE identifiers published by CISA"},"notes":{"type":"string","description":"Additional CISA KEV notes when supplied"},"cve_id":{"type":"string","description":"Exact CVE identifier matched in the CISA KEV catalog"},"product":{"type":"string","description":"Affected product label published by CISA"},"due_date":{"type":"string","description":"CISA KEV due date for covered federal agencies"},"date_added":{"type":"string","description":"Date CISA added the CVE to KEV"},"vendor_project":{"type":"string","description":"Vendor or project label published by CISA"},"required_action":{"type":"string","description":"Required action text published by CISA; caller remediation review is still required"},"short_description":{"type":"string","description":"Short vulnerability description published by CISA"},"vulnerability_name":{"type":"string","description":"CISA KEV vulnerability name"},"known_ransomware_campaign_use":{"type":"string","description":"CISA's published ransomware-campaign-use value when supplied"}},"description":"Exact CISA KEV match on a syntactically valid CVE ID or alias; omitted rather than null when no exact match exists","additionalProperties":false},"aliases":{"type":"array","items":{"type":"string"},"description":"Deduplicated lexical aliases published by OSV"},"summary":{"type":"string","description":"Bounded OSV summary"},"affected":{"type":"array","items":{"type":"object","required":["package","ranges","versions","severity"],"properties":{"ranges":{"type":"array","items":{"type":"object","required":["type","events"],"properties":{"repo":{"type":"string","description":"Repository identifier published by OSV for a GIT range"},"type":{"type":"string","description":"OSV range type such as SEMVER, ECOSYSTEM, or GIT"},"events":{"type":"array","items":{"type":"object","properties":{"fixed":{"type":"string","description":"OSV range event explicitly marking a fixed version"},"limit":{"type":"string","description":"OSV range event upper limit when supplied"},"introduced":{"type":"string","description":"OSV range event marking an introduced version"},"last_affected":{"type":"string","description":"OSV range event marking the last affected version"}},"description":"One OSV range event; exactly one event field is normally supplied by the source","additionalProperties":false},"description":"Ordered OSV range events; the bridge does not infer ecosystem version ordering"}},"description":"One affected version range published by OSV","additionalProperties":false},"description":"Affected ranges retained in OSV source order"},"package":{"type":"object","properties":{"name":{"type":"string","description":"Exact package name published by OSV"},"purl":{"type":"string","description":"Package URL published by OSV when supplied"},"ecosystem":{"type":"string","description":"Exact OSV ecosystem identifier"}},"description":"Exact affected package identity published by OSV","additionalProperties":false},"severity":{"type":"array","items":{"type":"object","required":["type","score"],"properties":{"type":{"type":"string","description":"OSV-declared score type such as CVSS_V3"},"score":{"type":"string","description":"Original published vector; malformed or mismatched vectors are retained but score as unknown"}},"description":"One severity vector exactly as published by OSV","additionalProperties":false},"description":"Severity vectors attached to this affected package entry"},"versions":{"type":"array","items":{"type":"string"},"description":"Affected versions explicitly enumerated by OSV"}},"description":"One OSV affected package entry retained in source order","additionalProperties":false},"description":"Bounded OSV affected package/range/event data in source order"},"modified":{"type":"string","description":"OSV modification time string"},"severity":{"type":"array","items":{"type":"object","required":["type","score"],"properties":{"type":{"type":"string","description":"OSV-declared score type such as CVSS_V3"},"score":{"type":"string","description":"Original published vector; malformed or mismatched vectors are retained but score as unknown"}},"description":"One severity vector exactly as published by OSV","additionalProperties":false},"maxItems":16,"description":"At most 16 published top-level OSV severity vectors"},"published":{"type":"string","description":"OSV publication time string when supplied"},"withdrawn":{"type":"boolean","description":"Whether OSV withdrew the record; withdrawn findings remain visible but do not count in the active summary"},"references":{"type":"array","items":{"type":"object","required":["type","url"],"properties":{"url":{"type":"string","description":"Reference URL supplied by OSV as untrusted provenance data; never fetched by this bridge"},"type":{"type":"string","description":"OSV reference classification such as ADVISORY, FIX, REPORT, or WEB"}},"description":"One OSV-published reference retained as provenance data","additionalProperties":false},"description":"Bounded references published by OSV; URLs are untrusted data returned for provenance and are never fetched by this bridge"},"max_severity":{"enum":["unknown","low","medium","high","critical"],"type":"string","description":"Highest severity derived only from a parseable declared CVSS vector"},"withdrawn_at":{"type":"string","description":"OSV withdrawal time string, present only when supplied"},"fixed_versions":{"type":"array","items":{"type":"string"},"description":"Only explicit fixed events for the matching package, deduplicated in OSV source order; [] means OSV supplied no fixed event, not that no fix exists"}},"description":"One complete normalized OSV vulnerability finding, limited to 48 KiB after JSON encoding, with optional exact CISA KEV enrichment","additionalProperties":false},"maxItems":8,"description":"Complete findings for this exact input; collectively all response items reference at most eight distinct OSV IDs; always [] for no_known_vulnerabilities or query_failed"},"error_code":{"type":"string","const":"upstream_error","description":"Generic non-sensitive code present only when status is query_failed"}},"description":"One position-preserving package result","additionalProperties":false},"maxItems":50,"description":"Complete or explicitly failed results in original caller input order, including duplicate positions; all items collectively reference at most eight distinct OSV IDs"},"warnings":{"type":"array","items":{"type":"string","description":"Bounded warning intended for caller action or interpretation"},"description":"Freshness and interpretation warnings; always [] when none"},"operation":{"type":"string","const":"batch-check","description":"Stable route operation identifier"},"retrieved_at":{"type":"string","format":"date-time","description":"UTC time this bridge completed the response; this is not an OSV publication or modification time"},"schema_version":{"type":"string","const":"dependency-risk-v1","description":"Version of the normalized Dependency Risk response contract"}},"description":"Complete transactional Dependency Risk response, limited to the native budget reserved below the 512 KiB deployed wire ceiling","additionalProperties":false}}}}},"category":"security"}},"description":"Batch dependency vulnerability check — check ordered exact package versions in OSV with deduplicated CVE enrichment, explicit completeness, and CISA KEV known-exploited signals.","lastUpdated":"2026-09-15T06:32:24.704Z","serviceName":"Open Source Vulnerability Check","x402Version":2}]}}