For example GHSA-x37h-cx7x-wm76 is an advisory, but is an imported advisory but it lacks a link to the repo, or the package.
The original data source in the cve https://nvd.nist.gov/vuln/detail/cve-2026-87736 includes the package name:
OCaml mirage-crypto-ec Affected 0 < 2.3.0 (semver)
Default Status: Unaffected
Package URL: pkg:opam/mirage-crypto-ec
The OSV data source includes it too, see: https://osv.dev/vulnerability/OSEC-2026-15
FWIW the actual source of truth for these advisories is hosted on github too in OSV JSON format: https://github.com/ocaml/security-advisories/tree/generated-osv if that'd be easier for you to fetch.
For example GHSA-x37h-cx7x-wm76 is an advisory, but is an imported advisory but it lacks a link to the repo, or the package.
The original data source in the cve https://nvd.nist.gov/vuln/detail/cve-2026-87736 includes the package name:
The OSV data source includes it too, see: https://osv.dev/vulnerability/OSEC-2026-15
FWIW the actual source of truth for these advisories is hosted on github too in OSV JSON format: https://github.com/ocaml/security-advisories/tree/generated-osv if that'd be easier for you to fetch.