OSV, for npm and PyPI
Epherem checks the npm and PyPI packages a project installs against OSV, the open-source vulnerability database. OSV collects its records from the sources below.
Sources and licences
| Source | Records for | Licence |
|---|---|---|
GitHub Advisory Database, by GitHub. Identifiers begin GHSA-. | npm, PyPI | CC BY 4.0 |
PyPI Advisory Database, by the Python Packaging Authority. Identifiers begin PYSEC-. | PyPI | CC BY 4.0 |
Erlang Ecosystem Foundation CNA. Identifiers begin EEF-. | npm | CC BY 4.0 |
OpenSSF Malicious Packages, by the Open Source Security Foundation. Identifiers begin MAL-. | npm, PyPI | Apache License 2.0 |
The sources and their licences are as OSV lists them in its data sources. The identifier shown with each dependency finding says which source a record came from.
How the records are changed
The records are not shown as their sources publish them. Epherem converts each record into its report format: it keeps the record's identifier, summary, affected versions and reference links, derives a severity from the record's own severity data, and matches the affected versions against the versions a project installs. Records under CC BY 4.0 are used under that licence, and these changes are made to them.
The bundled offline copy
When OSV cannot be reached, Epherem checks against a copy of these records that it keeps on its own servers, and the report marks its dependency check incomplete. That copy was last refreshed on .