Important update regarding OSS Index usage

We at Sonatype are committed to providing a high-quality, reliable service to all users of OSS Index. We are introducing rate limits and authentication requirements to ensure that the service remains available to everyone and to help manage our resources better.
Through registration and rate limits, we can better understand costs, performance levels, and ensure our service is not abused or violated by bad actors.
Starting April 24, 2023, unregistered users will be limited to 40 requests per month on OSS Index. We encourage you to create an account and authenticate with OSS Index to increase your usage limits. Authenticated users may have access to additional features and higher usage limits.
These changes are necessary to help ensure the long-term viability and sustainability of OSS Index for all users. We thank you for your understanding in advance.
If you have any questions or concerns, please don’t hesitate to contact us. Thank you for your continued support and use of OSS Index.

Sonatype OSS INDEX

Find Safe Components

OSS Index is a free catalogue of open source components and scanning tools to help developers identify vulnerabilities, understand risk, and keep their software safe.

Sign up today!

Get access to:

  • Vulnerability details for your components
  • Remediation insights
  • Higher rate limits for API and scans
Register for free

Search millions of components to find any known, publicly disclosed vulnerabilities across a wide range of ecosystems.

Search by name or by coordinates.


Scan your projects for open source vulnerabilities, and build security into your development toolchain with native tools and integrations. The following scan tools all utilize the OSS Index public REST API.



  • Nancy scans Golang projects




  • ossaudit scans Python projects
  • Jake scans Python and Conda projects


  • Bach scans Composer projects





Sonatype Lift installs as a Github app to automatically flag vulnerabilities on every pull request, and reports findings as comments in code review. Lift catches high-risk issues and screens out likely false-positives, helping you fix the things you care about most. See what Lift finds in your project.

Need DevSecOps at scale?

OSS Index and the associated tools are and always will be free to the community. The data we gather is derived from public sources, and does not include human curated intelligence nor expert remediation guidance.

Software development teams who want to scale with precise, curated, and highly actionable intelligence across their entire SDLC should check out the Nexus Platform. Release faster while controlling open source risk.

Nexus Firewall

Vet parts early and automatically stop defective open source components from entering your software supply chain

Nexus Repository

Manage libraries and store artifacts in a universal repository and share them across development teams

Nexus Lifecycle

Empower teams with precise component intelligence to enforce policies and continuously remediate risk

Nexus Lifecycle Foundation

Identify open source risk and remediate vulnerabilities with precise component intelligence at CI and deployment