OSV
for LuumenAI

Check packages, versions, and commits against the open vulnerability database

Ask what a package or commit is exposed to and get the answer in the terminal. OSV_QUERY_VULNERABILITIES covers one package, version, package URL, or commit; OSV_QUERY_VULNERABILITIES_BATCH checks up to 1,000 in one request. OSV_GET_VULNERABILITY returns the full record for an ID. Read-only, and no credential to configure.

The OSV toolbox

5 tools, all read-only. They answer instantly, and every call is logged.

  • ReadDetermine VersionExperimentally rank probable versions of an OSS-Fuzz C/C++ library from relative source-file paths and base64-encoded MD5 hashes.
  • ReadGet Import FindingsExperimentally list OSV records from one exact import source that failed import-time quality checks; intended for OSV source maintainers and may return no records.
  • ReadGet VulnerabilityReturn the complete OSV record for one case-sensitive vulnerability ID, including affected versions, ranges, severity, references, and aliases.
  • ReadQuery VulnerabilitiesFind full OSV vulnerability records affecting one package, package version, package URL, or commit.
  • ReadQuery Vulnerabilities BatchCheck up to 1,000 packages, package versions, package URLs, or commits in one request and return position-matched compact vulnerability IDs.

Questions

How does LuumenAI connect to OSV?

OSV needs no credential of its own, so there is nothing to authorize. Access is still granted per agent, skill, and team inside Luumen, and every call is logged.

Can LuumenAI change things in OSV on its own?

No. Every one of the 5 tools LuumenAI has for OSV is read-only, so it can answer questions from OSV but cannot change anything in it. Reads are not gated — they answer immediately, and each one is recorded on the audit trail with the actor and the result.

Who gets access to the integration?

You decide. Access is granted per agent, skill, and team, and per environment — production is not staging.

Is there an audit trail?

Every call to OSV is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put OSV to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.