changedInput schema / properties / findings / items / properties / advisoryId / description
Previous value: -"GHSA/OSV advisory id, passed through unchanged for reference"New value: +"GHSA/OSV advisory id, passed through unchanged for reference — a MAL-* id is auto-detected as malware even without findingType set"
addedInput schema / properties / findings / items / properties / findingType
Added value: +{
+ "description": "\"malware\" forces the remove-now tier regardless of score/CVE/severity — set this (or pass a MAL-* advisoryId) for a confirmed-malicious package. Omit for an ordinary vulnerability finding.",
+ "enum": [
+ "malware",
+ "vulnerability",
+ "supply-chain",
+ "install-script"
+ ],
+ "type": "string"
+}
addedOutput schema / properties / ranked / items / properties / findingType
Added value: +{
+ "enum": [
+ "malware",
+ "vulnerability",
+ "supply-chain",
+ "install-script"
+ ],
+ "type": "string"
+}
changedOutput schema / properties / ranked / items / properties / tier / enum
Previous value: -[
- "patch-now",
- "patch-soon",
- "scheduled",
- "monitor"
-]New value: +[
+ "remove-now",
+ "patch-now",
+ "patch-soon",
+ "scheduled",
+ "monitor"
+]
changedOutput schema / properties / ranked / items / required
Previous value: -[
- "rank",
- "packageName",
- "cveId",
- "advisoryId",
- "currentVersion",
- "fixedVersion",
- "severity",
- "kev",
- "epss",
- "score",
- "tier",
- "reason",
- "npmscanUrl",
- "cveNpmscanUrl"
-]New value: +[
+ "rank",
+ "packageName",
+ "cveId",
+ "advisoryId",
+ "currentVersion",
+ "fixedVersion",
+ "severity",
+ "kev",
+ "epss",
+ "score",
+ "tier",
+ "findingType",
+ "reason",
+ "npmscanUrl",
+ "cveNpmscanUrl"
+]
addedOutput schema / properties / summary / properties / removeNow
Added value: +{
+ "type": "number"
+}
changedOutput schema / properties / summary / required
Previous value: -[
- "patchNow",
- "patchSoon",
- "scheduled",
- "monitor",
- "kevListedCount"
-]New value: +[
+ "removeNow",
+ "patchNow",
+ "patchSoon",
+ "scheduled",
+ "monitor",
+ "kevListedCount"
+]