Network & Testing
Dependency Vulnerability Preflight
Look up exact npm package versions using the fixed public OSV provider.
Processed on our CPU server.Submitted input is processed for this run and is not stored. Only selected package names and versions are sent to api.osv.dev with your agreement. No lockfile content is sent.
256 KiB limitInput
Result
A useful result starts here.
Paste your input or load an example,
then run the tool.
Supported formats & limitations
- Explicit pairs OR npm package-lock v3. Lowercase npm name subset and exact SemVer only; ranges, workspace/link/local/git/nonstandard-registry dependencies remain unresolved.
- At most 50 unique resolved pairs, one fixed querybatch call, 256 KiB response and 200 advisories per pair. Pagination is incomplete; upstream failures remain unknown.
- Only selected name/version pairs are sent with explicit agreement; no private lockfile fields, persistent cache, installation, builds or scripts. No-match is not secure and matches do not prove installed bytes are affected.
- Only public HTTP port 80 / HTTPS port 443. Every DNS answer and redirect is validated, with pinned connections and no ambient credentials/cookies. Private/reserved/metadata addresses, custom ports, URL credentials and fragments are rejected.
Execution budget: 10s; output limit: 4096 KiB. Browser worker startup has a separate 3s allowance.