{"statement":"Ask Since.dev to watch the things your code depends on. The connectors below are maintained continuously. For other requests, Since.dev confirms that a suitable public source is available before creating the watch. You always see the exact sources or a clear reason the watch cannot be created.","connectors":[{"name":"npm","publisher":"npm, Inc.","description":"The published version, licence, and deprecation notice for a package, read from the per-version endpoint rather than the packument, which is three orders of magnitude larger.","serves":"Package versions, licences, and deprecations","homepageUrl":"https://www.npmjs.com","rights":"Public registry metadata read through npm's documented public API."},{"name":"PyPI","publisher":"the Python Package Index","description":"The published version, licence, Python requirement, and yank status for a project.","serves":"Package versions, licences, and yanks","homepageUrl":"https://pypi.org","rights":"Public project metadata published by the PSF for reuse."},{"name":"crates.io","publisher":"the Rust Foundation","description":"The published version, licence, and yank status for a Rust crate. The stable line is preferred when a newer pre-release exists.","serves":"Crate versions, licences, and yanks","homepageUrl":"https://crates.io","rights":"Public registry metadata read through the crates.io API, paced to its crawler policy of one request per second."},{"name":"RubyGems","publisher":"Ruby Central","description":"The published version, licence, and project links for a Ruby gem.","serves":"Gem versions and licences","homepageUrl":"https://rubygems.org","rights":"Public gem metadata read through the RubyGems.org API."},{"name":"Packagist","publisher":"Packagist Conductors","description":"The newest tagged release of a PHP package: version, licence, and description. Dev snapshots never count as a release.","serves":"Composer package versions and licences","homepageUrl":"https://packagist.org","rights":"Public package metadata read through Packagist's repository API."},{"name":"Go module proxy","publisher":"the Go project","description":"The latest published version of a Go module and when it appeared. The proxy carries no licence or description metadata, and the state says no more than that.","serves":"Go module versions","homepageUrl":"https://proxy.golang.org","rights":"Public module metadata read through the proxy.golang.org API."},{"name":"OSV","publisher":"Open Source Vulnerabilities (OSV)","description":"Security advisories affecting a package, aggregated across ecosystems. Advisories are revised in place after publication, so a revision wakes you as well as the first disclosure.","serves":"Security advisories","homepageUrl":"https://osv.dev","rights":"Open advisory database published under a permissive licence."},{"name":"CISA KEV","publisher":"Cybersecurity and Infrastructure Security Agency","description":"CVEs with confirmed exploitation in the wild, with the vendor, product, required action, and the remediation deadline CISA assigns. An entry appearing here is a signal to patch now, not eventually.","serves":"Actively exploited vulnerabilities","homepageUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","rights":"U.S. government vulnerability catalog published for public use."},{"name":"Vendor status pages","publisher":"The vendor operating the status page","description":"The overall operational indicator a service publishes about itself, for agents that need to know whether a dependency is degraded before retrying against it.","serves":"Service status and incidents","homepageUrl":null,"rights":"Read through the vendor's own documented status API."},{"name":"OpenAPI documents","publisher":"The API's own publisher","description":"A published OpenAPI document read structurally: operations appearing, disappearing, or being marked deprecated, schema changes by name, and the API's own version moving.","serves":"API operations, schemas, and deprecations","homepageUrl":null,"rights":"A machine-readable specification the publisher serves for consumption."},{"name":"GitHub","publisher":"GitHub, Inc.","description":"Repository state and published releases for open-source projects.","serves":"Releases and repository activity","homepageUrl":"https://github.com","rights":"Public repository metadata read through GitHub's documented public API."},{"name":"Official RSS and Atom feeds","publisher":"The publisher of the feed","description":"A publisher's own machine-readable announcement feed.","serves":"A publisher's own announcements","homepageUrl":null,"rights":"Read under the publisher's robots.txt; short factual summaries only."},{"name":"Public web pages","publisher":"The site owner","description":"A specific public page, or a region of one, watched for substantive change.","serves":"Page content and prices","homepageUrl":null,"rights":"Read under the site's robots.txt. Never behind a paywall or a login, and never republished."}],"boundaries":["Since.dev respects robots.txt and never bypasses a paywall or a login.","Since.dev states what changed and cites the source. It does not republish source content.","Private registries, sources behind an account, and anything a publisher's terms close to automated reading are not covered."]}