DepVet developer guides
Practical, copy-paste guides for calling DepVet from your own code. Every endpoint is paid per call in USDC on Base via x402, with no API key.
- Check an npm package for malware before you install it: Check an npm or PyPI package for malware advisories, known CVEs, typosquats and deprecation before install with one API call returning OK, REVIEW or AVOID.
- Detect typosquatting in package.json dependencies: Scan the dependency names in package.json for typosquats of popular npm packages, up to 20 per call, with an OK, REVIEW or AVOID verdict for each.
- Scan a lockfile for vulnerable dependencies in CI or agents: Check up to 20 npm or PyPI packages per call for CVEs, malware advisories, typosquats and license risk. Batch a package-lock.json in CI or inside an agent.
DepVet overview/openapi.jsonllms.txt
Sister services
- BaseLens: Base chain tools: tx explainer, wallet snapshot, x402 endpoint check, web-to-markdown
- TokenGuard: honeypot and rug pull checks for Base tokens, plus pre-screened new launches
- MacroLens: country macro statistics and company registries (Norway, France)
- SkyFeed: weather forecasts, US alerts, earthquakes and public holidays
- ChainRead: gas, balances, ENS and Basename resolution on Base and Ethereum