submit-threat endpoint lets you submit threat reports programmatically without using the web interface. Submitted reports enter the community verification process and are only published after passing review.
Use this endpoint to:
- Automate reporting from your tooling: Flag suspicious packages the moment your internal detection systems identify them, without switching to the web UI.
- Integrate with security pipelines: Trigger submissions directly from CI/CD workflows, dependency scanners, or SIEM alerts.
- Contribute at scale: Research teams and Research Partners can submit structured threat reports in bulk via API.
Submitted reports go through the community verification process before they are published to the database. This review ensures data quality and prevents false positives. You can track the status of your submissions from your profile on opensourcemalware.com.

