npm package security data: npm API vs Snyk vs OSV vs GitHub Advisory
Sources for npm supply-chain incident data compared: advisories, malware timelines, IOC feeds, and which is machine-readable for free.
Sources compared
| Source | Access | Price | ISIN | Coverage | Update cadence |
|---|---|---|---|---|---|
| npm registry API | Open API | Free | no | Package metadata, deprecation | Live |
| GitHub Advisory Database | Open | Free | no | CVE-linked advisories | Live |
| OSV.dev | Open API | Free | no | Aggregated vulns across ecosystems | Live |
| Our timeline (vhsgreed) | One-time purchase | $3 | no | 2026 incidents: timeline, affected packages, IOCs | Snapshot 2026-08 |
npm registry API: No security timeline; you must correlate incidents yourself.
GitHub Advisory Database: CVE-shaped; supply-chain attacks lag in it.
OSV.dev: Best free structured source for known vulns.
Our timeline (vhsgreed): Incident-shaped (attack narratives + IOCs), not CVE-shaped.
What our data adds
- Incident timeline CSV with affected-package mapping
- IOC list (domains, packages, commit hashes) as CSV
- Report PDF correlating each incident to response actions
Get the data
npm Supply-Chain Attack Timeline 2026
$3
More comparisons
- Swedish stock market data sources: free vs paid compared
- Swedish company data: Bolagsverket vs allabolag vs SCB vs our CSV
- Robotics datasets: 12 sources compared (supply chain, stocks, standards)
- Hemnet data access options compared (listings, sold prices, ToS reality)
- Free stock data APIs for Nordic markets: what actually works