Public change record

Sources and coverage

Public sources checked by Since.dev. Private registries and sources behind an account are outside this coverage.

npm

npm, Inc.

Published versions, licence information, and deprecation notices for npm packages.

Public registry metadata read through npm's documented public API.

PyPI

the Python Package Index

The published version, licence, Python requirement, and yank status for a project.

Public project metadata published by the PSF for reuse.

crates.io

the Rust Foundation

The published version, licence, and yank status for a Rust crate. The stable line is preferred when a newer pre-release exists.

Public registry metadata read through the crates.io API under its usage policy.

RubyGems

Ruby Central

The published version, licence, and project links for a Ruby gem.

Public gem metadata read through the RubyGems.org API.

Packagist

Packagist Conductors

The newest tagged release of a PHP package: version, licence, and description. Dev snapshots never count as a release.

Public package metadata read through Packagist's repository API.

Go module proxy

the Go project

The latest published version of a Go module and its publication date.

Public module metadata read through the proxy.golang.org API.

OSV

Open Source Vulnerabilities (OSV)

Security advisories affecting packages across supported ecosystems, including updates to published advisories.

Open advisory database published under a permissive licence.

CISA KEV

Cybersecurity and Infrastructure Security Agency

CVEs with confirmed exploitation in the wild, with the vendor, product, required action, and the remediation deadline CISA assigns. An entry appearing here is a signal to patch now, not eventually.

U.S. government vulnerability catalog published for public use.

Vendor status pages

The vendor operating the status page

The overall operational indicator a service publishes about itself, for agents that need to know whether a dependency is degraded before retrying against it.

Read through the vendor's own documented status API.

OpenAPI documents

The API's own publisher

Changes to published API operations, schemas, deprecations, and versions.

A machine-readable specification the publisher serves for consumption.

GitHub

GitHub, Inc.

Repository state and published releases for open-source projects.

Public repository metadata read through GitHub's documented public API.

Official RSS and Atom feeds

The publisher of the feed

A publisher's own machine-readable announcement feed.

Read under the publisher's robots.txt; short factual summaries only.

Public web pages

The site owner

A specific public page, or a region of one, watched for substantive change.

Read under the site's robots.txt. Never behind a paywall or a login, and never republished.

Changes · Sources · Documentation