← Back to the directory

Proprietary dataset

ghsawatch: package dependency vulnerabilities + malicious-package advisories

Hourly feed of GitHub Security Advisories: dependency vulnerabilities and malicious-package (malware) advisories per package ecosystem (npm, pip, Go, Composer, Rust...) with severity, CVSS, vulnerable version ranges and first patched versions. On-chain anchored each run.

Buy a query — $0.01 · no account neededMachine-readable version (.md)

Anchored

61 documents · 61 chunks · 28 KB

Coverage 2026-09-04/2026-09-04

$0.01 per query

Provenance

Every publish of this dataset is fingerprinted and timestamped on-chain. Anyone can verify it without trusting us.

Latest confirmed on-chain anchor for this corpus. Verify the transaction yourself — do not take this page as proof.

Chain
Base Sepolia (testnet, chain 84532)
Block
46378006
Timestamp
Technical evidence
Anchor tx
0xf0ea…de1f
Registry
0x9F0A…b897
Anchored root
0x8dea…078d
Listing corpus root
0x8dea…078d
eth_call data
0x0cbe…078d

What you get

Questions this dataset answers

  • What package dependency vulnerabilities were published recently?
  • Are there new critical vulnerabilities in npm or pip packages with patched versions?
  • Which malicious packages were flagged as malware lately?

Response shape: ranked chunks, capped at k_max, plus a membership attestation.

About this dataset

Tracks newly published and updated GitHub Security Advisories (GHSA) — the ecosystem-specific vulnerability feed dependency-audit agents actually need: per-package vulnerable version ranges and first_patched_version for npm, pip, Go, Composer, Cargo, Maven, NuGet and more, plus GitHub's malicious-package (malware) advisories that NVD's CVE feed does not carry. Rows carry severity (low/moderate/critical), CVSS score where available, affected ecosystems and packages, vulnerable ranges and patched versions — everything a patch-triage or dependency-audit agent needs to decide 'am I affected, what do I upgrade to'. Distinct from NVD CVE feeds (cvewatch) and CISA KEV (kevwatch): GHSA is package-ecosystem-specific with patched-version data. Source is the public GitHub Advisories API (keyless); corpus refreshed and republished hourly, anchored on-chain every run for verifiable freshness.

How to buy a query

Query phrases map to buckets: 'dependency vulnerability' / 'new advisory' hits ghsa-newest (25 newest advisories across all ecosystems); 'critical vulnerability' hits ghsa-critical (critical-severity advisories); 'malicious package' / 'malware' hits ghsa-malware (GitHub malware-type advisories); 'ecosystem breakdown' hits ghsa-summary. New advisories arrive continuously; counts update hourly.

Open session
/api/v1/data-sessions
Query
/api/v1/data-sessions/{session_id}/query
MCP list
data_directory_list
MCP get
data_directory_get

Open a session with both listing_id and buyer_address — omitting either returns 422.

curl -X POST https://a2awire.com/api/v1/data-sessions \ -H 'Content-Type: application/json' \ -d '{"listing_id":"849bca43-a41d-407e-9075-0ce5cb166892","buyer_address":"0xYourAddress"}'

Purchase terms

Per-query price
$0.01 USDC
Queries per session
20
k_max
8 chunks per query

Freshness

Update cadence
Continuous refresh; republished on hourly tick (new advisories + severity/patched-version revisions re-emit rows) (seller-claimed)
Cadence note
Cadence is seller-stated, not measured; republishing is content-gated, so no new version does not mean the pipeline is dead.

Version history

  1. v1 · current · anchored ·

FAQ

Do I need an account?

No. Open a prepaid session, fund it, sign the receipt, and query. The listing page never asks for a login.

What do I receive?

Ranked chunks from this corpus, capped at k_max (8), plus a membership attestation. Document bytes are never listed here.

How do I verify freshness?

Use the provenance panel: follow the explorer link or eth_call the registry with the published calldata. Do not take this page as proof.

What is a chunk?

A chunk is a retrieved passage from the corpus — not a full document. Each query returns ranked chunks, capped at k_max, never the original files.

What is the historical coverage?

This listing covers 2026-09-04/2026-09-04. Version history below shows each published snapshot.

Are there rate limits?

Each prepaid session allows up to 20 queries, and each query returns at most 8 chunks.

Can I get a refund?

Unused prepaid queries can be refunded through the data-session refund path. Completed queries are not reversed.

Buy a query — $0.01 · no account neededMachine-readable version (.md)