PG1 credits every third-party data source it serves data from. This page lists the sources behind the check_package tool and the licence or terms each is used under. Each check_package response links here in its attribution field.
Advisory databases
Malicious-package reports and vulnerability ids come from these databases, queried through OSV.dev, the query service that serves the advisory databases above. PG1 shows only an advisory's id and severity, never its text.
| Source | Used for | Licence |
|---|---|---|
| OpenSSF Malicious Packages | reports of malicious packages (reported_malicious, malicious_reports) | Apache-2.0 |
| GitHub Advisory Database | vulnerability ids and severity | CC-BY 4.0 |
| PyPI Advisory Database | vulnerability ids and severity for PyPI packages | CC-BY 4.0 |
| Go Vulnerability Database | vulnerability ids and severity, when OSV returns them | CC-BY 4.0 |
| RustSec Advisory Database | vulnerability ids and severity, when OSV returns them | CC0 1.0 |
Only advisories whose id starts with MAL-, GHSA-, PYSEC-, GO- or RUSTSEC- are shown. Anything else the query service returns is left out and counted in vulnerabilities_omitted. Distribution-specific databases (for example Ubuntu or Debian security notices) are never used.
"Reported malicious" means a public report exists in OpenSSF Malicious Packages. Such reports can be false positives, so PG1 never words them as a finding of its own.
Package registries
| Source | Used for | Terms |
|---|---|---|
| npm public registry | npm package metadata: whether a package and version exist, publish dates, deprecation and install scripts | npm Open-Source Terms |
| PyPI (the Python Package Index) | PyPI package metadata: whether a package and version exist, and publish dates | PyPI Terms of Use |
PG1 looks up one package per request, caches each answer (registry metadata for 1 hour, malicious-package status for 15 minutes), uses short timeouts, identifies itself in its User-Agent, and never crawls a registry in bulk.
What PG1 keeps
Nothing from a check is stored beyond the in-memory caches above. Usage telemetry records the tool name, how the call ended, its latency and a salted hash of the caller IP, never the package name or version.