vulnerability-db

(β˜… 146)

Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.

  • .dockerignore
  • .flake8
  • .gitignore
  • AGENTS.md
  • conftest.py
  • INTEGRATION.md
  • LICENSE
  • MIGRATING_TO_V7.md
  • pyproject.toml
  • README.md
  • SECURITY.md
  • SKILL.md
  • THREAT_MODEL.md
  • uv.lock

# Installation Guide

1. Get the code
git clone https://github.com/AppThreat/vulnerability-db

Downloads the entire project code from GitHub to your computer.

cd vulnerability-db

Moves into the project folder you just downloaded.

2. Official Install Script

Easy Recommended
Prerequisites
  • Python 3 Python is required to use pip.
pip install appthreat-vulnerability-db>=7.0.0

Installs the package published on PyPI directly β€” no need to clone the source.

pip install appthreat-vulnerability-db[all]

Installs the package published on PyPI directly β€” no need to clone the source.

pip install appthreat-vulnerability-db==5.8.0

Installs the package published on PyPI directly β€” no need to clone the source.

pip install -U "huggingface_hub[cli]"

Installs the package published on PyPI directly β€” no need to clone the source.

βœ… After installing, open a new terminal and run the program's version command (e.g. --version) to confirm it worked.

Pulled directly from this repo's README.

3. Docker

Easy
Prerequisites
  • Git Needed to download the project code from GitHub.
  • Docker Desktop Needed to build and run containers. Install it and keep it running in the background.
⚠️ This is a large repository, so this method may point to an internal sub-package rather than the actual core product. Check the full README as well.
docker build -f packages/mcp-server-vdb/Dockerfile -t vulnerability-db .

Builds a runnable image based on the Dockerfile.

docker run -p 8080:80 vulnerability-db

Runs the built image as an actual container.

βœ… Run docker compose ps to check the containers are Up. If the README mentions a port, open http://localhost:PORT in your browser.

4. Node.js

Easy
Prerequisites
  • Git Needed to download the project code from GitHub.
  • Node.js Node.js must be installed to use npm. The LTS version is recommended.
vdb db refresh npm pypi # named shards (shard names or purl types; nuget resolves to app)

Type this command into your terminal and run it.

ghcr.io/appthreat/vdb7-npm:v7.0.x-xz one purl type

Type this command into your terminal and run it.

hf download --repo-type dataset AppThreat/vdb v7-npm/data.vdb7 # raw .vdb7

Type this command into your terminal and run it.

vdb --search "cpe:2.3:a:npm:gitblame:*:*:*:*:*:*:*:*"

Type this command into your terminal and run it.

vdb --search "npm:gitblame:0.0.1" # colon-separated

Type this command into your terminal and run it.

βœ… After running the command, open the address shown in the terminal (usually something like http://localhost:3000) in your browser.

Pulled directly from this repo's README.

5. Python

Easy
Prerequisites
  • Git Needed to download the project code from GitHub.
  • Python 3 On Windows, be sure to check 'Add Python to PATH' during installation.
pip install appthreat-vulnerability-db>=7.0.0

Installs the package published on PyPI directly β€” no need to clone the source.

pip install appthreat-vulnerability-db[all]

Installs the package published on PyPI directly β€” no need to clone the source.

pip install appthreat-vulnerability-db==5.8.0

Installs the package published on PyPI directly β€” no need to clone the source.

pip install -U "huggingface_hub[cli]"

Installs the package published on PyPI directly β€” no need to clone the source.

βœ… If it runs without errors and prints output in the terminal, it worked.

Pulled directly from this repo's README.

// repository documentation