2026 Quick-Reference Cheat Sheet & Benchmark Table: Live package.json & requirements.txt CVE Dependency Auditor
Your browser parses the package names and version numbers locally and sends a batch query to Google's open-source **OSV.dev API** (`api.osv.dev`), which aggregates live advisories from the **GitHub Security Advisory Database (GHSA)**, **National Vulnerability Database (NVD)**, **PyPA Advisory Database (PYSEC)**, and **RustSec/GoVulnDB**. Use this interactive package json vulnerability scanner osv above to test online package.json cve security scanner, requirements.txt vulnerability checker osv.dev, and github security advisory dependency auditor locally in your browser with zero server uploads.
Target Keyword Spec: package json vulnerability scanner osv | Modules: Live Google OSV.dev & GitHub Advisory (GHSA/CVE) Batch Query Engine • SemVer Range Normalizer & Pinning Hygiene Linter • CVSS Severity Breakdown & Patched Version Resolver| Technical Parameter / Module | Standard / Keyword Spec | Architecture & Validation Rule | Operational Use Case (2026) |
|---|---|---|---|
| Live Google OSV.dev & GitHub Advisory (GHSA/CVE) Batch Query Engine | online package.json cve security scanner | Parse `dependencies` and `devDependencies` from `package.json` or pinned pa... | Rapid CI/CD & Pull Request Dependency Triage |
| SemVer Range Normalizer & Pinning Hygiene Linter | requirements.txt vulnerability checker osv.dev | Strip caret (`^`), tilde (`~`), and `>=` range operators to test resolved v... | Auditing Legacy Repositories Before Running `npm install` |
| CVSS Severity Breakdown & Patched Version Resolver | github security advisory dependency auditor | Inspect full advisory details including GHSA/CVE/PYSEC identifiers, CVSS v3... | DevSecOps Supply-Chain Pinning & SBOM Hygiene |
| Execution & Privacy Architecture | 100% Client-Side WebCrypto / JS Sandbox | 0 Bytes Sent to External Servers | Safe for internal SOC & authorized lab artifacts |
| NIST SP 800-53 / OWASP Alignment | OWASP ASVS v4.0.3 / NIST CSF 2.0 | Deterministic Rule & Header Verification | Maps findings to actionable hardening controls |
| Cryptographic & Entropy Standard | SHA-256 / AES-256-GCM / Argon2id | ≥ 128-bit Effective Security Margin | Meets 2026 post-quantum & zero-trust baselines |
