PG1

PG1 reference

Data sources and licences

PG1 credits every third-party data source it serves data from. This page lists the sources behind the check_package tool and the licence or terms each is used under. Each check_package response links here in its attribution field.

Advisory databases

Malicious-package reports and vulnerability ids come from these databases, queried through OSV.dev, the query service that serves the advisory databases above. PG1 shows only an advisory's id and severity, never its text.

SourceUsed forLicence
OpenSSF Malicious Packagesreports of malicious packages (reported_malicious, malicious_reports)Apache-2.0
GitHub Advisory Databasevulnerability ids and severityCC-BY 4.0
PyPI Advisory Databasevulnerability ids and severity for PyPI packagesCC-BY 4.0
Go Vulnerability Databasevulnerability ids and severity, when OSV returns themCC-BY 4.0
RustSec Advisory Databasevulnerability ids and severity, when OSV returns themCC0 1.0

Only advisories whose id starts with MAL-, GHSA-, PYSEC-, GO- or RUSTSEC- are shown. Anything else the query service returns is left out and counted in vulnerabilities_omitted. Distribution-specific databases (for example Ubuntu or Debian security notices) are never used.

"Reported malicious" means a public report exists in OpenSSF Malicious Packages. Such reports can be false positives, so PG1 never words them as a finding of its own.

Package registries

SourceUsed forTerms
npm public registrynpm package metadata: whether a package and version exist, publish dates, deprecation and install scriptsnpm Open-Source Terms
PyPI (the Python Package Index)PyPI package metadata: whether a package and version exist, and publish datesPyPI Terms of Use

PG1 looks up one package per request, caches each answer (registry metadata for 1 hour, malicious-package status for 15 minutes), uses short timeouts, identifies itself in its User-Agent, and never crawls a registry in bulk.

What PG1 keeps

Nothing from a check is stored beyond the in-memory caches above. Usage telemetry records the tool name, how the call ended, its latency and a salted hash of the caller IP, never the package name or version.