npm
npm, Inc.
Published versions, licence information, and deprecation notices for npm packages.
Public registry metadata read through npm's documented public API.
Public change record
Public sources checked by Since.dev. Private registries and sources behind an account are outside this coverage.
npm, Inc.
Published versions, licence information, and deprecation notices for npm packages.
Public registry metadata read through npm's documented public API.
the Python Package Index
The published version, licence, Python requirement, and yank status for a project.
Public project metadata published by the PSF for reuse.
the Rust Foundation
The published version, licence, and yank status for a Rust crate. The stable line is preferred when a newer pre-release exists.
Public registry metadata read through the crates.io API under its usage policy.
Ruby Central
The published version, licence, and project links for a Ruby gem.
Public gem metadata read through the RubyGems.org API.
Packagist Conductors
The newest tagged release of a PHP package: version, licence, and description. Dev snapshots never count as a release.
Public package metadata read through Packagist's repository API.
the Go project
The latest published version of a Go module and its publication date.
Public module metadata read through the proxy.golang.org API.
Open Source Vulnerabilities (OSV)
Security advisories affecting packages across supported ecosystems, including updates to published advisories.
Open advisory database published under a permissive licence.
Cybersecurity and Infrastructure Security Agency
CVEs with confirmed exploitation in the wild, with the vendor, product, required action, and the remediation deadline CISA assigns. An entry appearing here is a signal to patch now, not eventually.
U.S. government vulnerability catalog published for public use.
The vendor operating the status page
The overall operational indicator a service publishes about itself, for agents that need to know whether a dependency is degraded before retrying against it.
Read through the vendor's own documented status API.
The API's own publisher
Changes to published API operations, schemas, deprecations, and versions.
A machine-readable specification the publisher serves for consumption.
GitHub, Inc.
Repository state and published releases for open-source projects.
Public repository metadata read through GitHub's documented public API.
The publisher of the feed
A publisher's own machine-readable announcement feed.
Read under the publisher's robots.txt; short factual summaries only.
The site owner
A specific public page, or a region of one, watched for substantive change.
Read under the site's robots.txt. Never behind a paywall or a login, and never republished.