vhsgreed
BlogDataAPIStore

npm package security data: npm API vs Snyk vs OSV vs GitHub Advisory

Sources for npm supply-chain incident data compared: advisories, malware timelines, IOC feeds, and which is machine-readable for free.

Sources compared

SourceAccessPriceISINCoverageUpdate cadence
npm registry API Open API Free no Package metadata, deprecation Live
GitHub Advisory Database Open Free no CVE-linked advisories Live
OSV.dev Open API Free no Aggregated vulns across ecosystems Live
Our timeline (vhsgreed) One-time purchase $3 no 2026 incidents: timeline, affected packages, IOCs Snapshot 2026-08

npm registry API: No security timeline; you must correlate incidents yourself.

GitHub Advisory Database: CVE-shaped; supply-chain attacks lag in it.

OSV.dev: Best free structured source for known vulns.

Our timeline (vhsgreed): Incident-shaped (attack narratives + IOCs), not CVE-shaped.

What our data adds

  • Incident timeline CSV with affected-package mapping
  • IOC list (domains, packages, commit hashes) as CSV
  • Report PDF correlating each incident to response actions

Get the data

npm Supply-Chain Attack Timeline 2026
$3
Get the data

More comparisons

All data comparisons