changedOutput schema / oneOf
Previous value: -[
- {
- "additionalProperties": false,
- "properties": {
- "coverage": {
- "description": "What the answer covers; null where the answer says nothing about it.",
- "type": "null"
- },
- "data": {
- "additionalProperties": {},
- "properties": {
- "advisory_id": {
- "type": [
- "string",
- "null"
- ]
- },
- "affected_products": {
- "anyOf": [
- {
- "items": {
- "type": "string"
- },
- "type": "array"
- },
- {
- "type": "null"
- }
- ]
- },
- "cve_ids": {
- "anyOf": [
- {
- "items": {
- "type": "string"
- },
- "type": "array"
- },
- {
- "type": "null"
- }
- ]
- },
- "cvss_v3_score": {
- "type": [
- "number",
- "null"
- ]
- },
- "description": {
- "type": [
- "string",
- "null"
- ]
- },
- "known_cve_ids": {
- "anyOf": [
- {
- "items": {
- "type": "string"
- },
- "type": "array"
- },
- {
- "type": "null"
- }
- ],
- "description": "The CVE IDs of cve_ids that have a record in EchelonGraph's CVE feed."
- },
- "our_first_seen_at": {
- "description": "When EchelonGraph first recorded the advisory; not the vendor's date.",
- "type": [
- "string",
- "null"
- ]
- },
- "references": {},
- "remediation": {
- "type": [
- "string",
- "null"
- ]
- },
- "severity": {
- "type": [
- "string",
- "null"
- ]
- },
- "summary": {
- "type": [
- "string",
- "null"
- ]
- },
- "title": {
- "type": [
- "string",
- "null"
- ]
- },
- "vendor": {
- "type": [
- "string",
- "null"
- ]
- },
- "vendor_advisory_id": {
- "type": [
- "string",
- "null"
- ]
- },
- "vendor_display_name": {
- "type": [
- "string",
- "null"
- ]
- },
- "vendor_modified_at": {
- "type": [
- "string",
- "null"
- ]
- },
- "vendor_published_at": {
- "description": "The date the vendor gives for the advisory.",
- "type": [
- "string",
- "null"
- ]
- },
- "withdrawn": {
- "description": "true: the vendor withdrew (rescinded) this advisory; report it as withdrawn.",
- "type": [
- "boolean",
- "null"
- ]
- },
- "withdrawn_at": {
- "type": [
- "string",
- "null"
- ]
- },
- "withdrawn_reason": {
- "type": [
- "string",
- "null"
- ]
- }
- },
- "type": "object"
- },
- "freshness": {
- "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
- "type": "null"
- },
- "measured_at": {
- "anyOf": [
- {
- "description": "An RFC 3339 instant.",
- "type": "string"
- },
- {
- "type": "null"
- }
- ],
- "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
- },
- "method": {
- "description": "How the numbers were produced.",
- "type": "string"
- },
- "notes": {
- "description": "Caveats, one sentence each.",
- "items": {
- "type": "string"
- },
- "type": "array"
- },
- "state": {
- "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
- "enum": [
- "measured",
- "not_assessed"
- ],
- "type": "string"
- }
- },
- "required": [
- "state",
- "measured_at",
- "method",
- "coverage",
- "freshness",
- "notes",
- "data"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "coverage": {
- "type": "null"
- },
- "error": {
- "additionalProperties": false,
- "properties": {
- "kind": {
- "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
- "enum": [
- "network",
- "timeout",
- "http",
- "not_json",
- "not_object",
- "invalid_input",
- "internal",
- "unexpected_shape",
- "radars"
- ],
- "type": "string"
- },
- "message": {
- "description": "The cause: the API's own message, or what went wrong.",
- "type": "string"
- },
- "path": {
- "description": "The API path requested, when a request was made.",
- "type": [
- "string",
- "null"
- ]
- },
- "status": {
- "anyOf": [
- {
- "maximum": 9007199254740991,
- "minimum": -9007199254740991,
- "type": "integer"
- },
- {
- "type": "null"
- }
- ],
- "description": "The HTTP status, when the API answered one."
- }
- },
- "required": [
- "kind",
- "path",
- "status",
- "message"
- ],
- "type": "object"
- },
- "freshness": {
- "type": "null"
- },
- "measured_at": {
- "type": "null"
- },
- "method": {
- "type": "null"
- },
- "notes": {
- "description": "Caveats, one sentence each.",
- "items": {
- "type": "string"
- },
- "type": "array"
- },
- "state": {
- "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
- "enum": [
- "failed",
- "invalid_input"
- ],
- "type": "string"
- }
- },
- "required": [
- "state",
- "measured_at",
- "method",
- "coverage",
- "freshness",
- "notes",
- "error"
- ],
- "type": "object"
- }
-]New value: +[
+ {
+ "additionalProperties": false,
+ "properties": {
+ "coverage": {
+ "anyOf": [
+ {
+ "additionalProperties": false,
+ "properties": {
+ "vendor_window": {
+ "anyOf": [
+ {
+ "additionalProperties": false,
+ "properties": {
+ "advisories": {
+ "description": "How many advisories EchelonGraph holds from this vendor, withdrawn ones not counted.",
+ "type": [
+ "number",
+ "null"
+ ]
+ },
+ "earliest_vendor_published_at": {
+ "description": "The earliest vendor_published_at among them; null when none is held. An advisory this vendor published before it is not held.",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "history_backfill": {
+ "anyOf": [
+ {
+ "anyOf": [
+ {
+ "enum": [
+ "complete",
+ "in_progress",
+ "not_started",
+ "not_supported"
+ ],
+ "type": "string"
+ },
+ {
+ "type": "string"
+ }
+ ]
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried)."
+ },
+ "latest_vendor_published_at": {
+ "description": "The latest vendor_published_at among them; null when none is held.",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "vendor": {
+ "description": "The vendor slug.",
+ "type": "string"
+ },
+ "vendor_display_name": {
+ "type": [
+ "string",
+ "null"
+ ]
+ }
+ },
+ "required": [
+ "vendor",
+ "vendor_display_name",
+ "advisories",
+ "earliest_vendor_published_at",
+ "latest_vendor_published_at",
+ "history_backfill"
+ ],
+ "type": "object"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "This advisory's vendor's window in what EchelonGraph holds; null when the windows could not be read or carry none for this vendor."
+ }
+ },
+ "required": [
+ "vendor_window"
+ ],
+ "type": "object"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "What the answer covers; null where the answer says nothing about it."
+ },
+ "data": {
+ "additionalProperties": {},
+ "properties": {
+ "advisory_id": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "affected_products": {
+ "anyOf": [
+ {
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ {
+ "type": "null"
+ }
+ ]
+ },
+ "cve_ids": {
+ "anyOf": [
+ {
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ {
+ "type": "null"
+ }
+ ]
+ },
+ "cvss_v3_score": {
+ "type": [
+ "number",
+ "null"
+ ]
+ },
+ "description": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "known_cve_ids": {
+ "anyOf": [
+ {
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "The CVE IDs of cve_ids that have a record in EchelonGraph's CVE feed."
+ },
+ "our_first_seen_at": {
+ "description": "When EchelonGraph first recorded the advisory; not the vendor's date.",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "references": {},
+ "remediation": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "severity": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "summary": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "title": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "vendor": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "vendor_advisory_id": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "vendor_display_name": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "vendor_modified_at": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "vendor_published_at": {
+ "description": "The date the vendor gives for the advisory.",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "withdrawn": {
+ "description": "true: the vendor withdrew (rescinded) this advisory; report it as withdrawn.",
+ "type": [
+ "boolean",
+ "null"
+ ]
+ },
+ "withdrawn_at": {
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "withdrawn_reason": {
+ "type": [
+ "string",
+ "null"
+ ]
+ }
+ },
+ "type": "object"
+ },
+ "freshness": {
+ "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
+ "type": "null"
+ },
+ "measured_at": {
+ "anyOf": [
+ {
+ "description": "An RFC 3339 instant.",
+ "type": "string"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
+ },
+ "method": {
+ "description": "How the numbers were produced.",
+ "type": "string"
+ },
+ "notes": {
+ "description": "Caveats, one sentence each.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "state": {
+ "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
+ "enum": [
+ "measured",
+ "not_assessed"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "state",
+ "measured_at",
+ "method",
+ "coverage",
+ "freshness",
+ "notes",
+ "data"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "coverage": {
+ "anyOf": [
+ {
+ "additionalProperties": false,
+ "properties": {
+ "vendor_window": {
+ "anyOf": [
+ {
+ "additionalProperties": false,
+ "properties": {
+ "advisories": {
+ "description": "How many advisories EchelonGraph holds from this vendor, withdrawn ones not counted.",
+ "type": [
+ "number",
+ "null"
+ ]
+ },
+ "earliest_vendor_published_at": {
+ "description": "The earliest vendor_published_at among them; null when none is held. An advisory this vendor published before it is not held.",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "history_backfill": {
+ "anyOf": [
+ {
+ "anyOf": [
+ {
+ "enum": [
+ "complete",
+ "in_progress",
+ "not_started",
+ "not_supported"
+ ],
+ "type": "string"
+ },
+ {
+ "type": "string"
+ }
+ ]
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried)."
+ },
+ "latest_vendor_published_at": {
+ "description": "The latest vendor_published_at among them; null when none is held.",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "vendor": {
+ "description": "The vendor slug.",
+ "type": "string"
+ },
+ "vendor_display_name": {
+ "type": [
+ "string",
+ "null"
+ ]
+ }
+ },
+ "required": [
+ "vendor",
+ "vendor_display_name",
+ "advisories",
+ "earliest_vendor_published_at",
+ "latest_vendor_published_at",
+ "history_backfill"
+ ],
+ "type": "object"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "This advisory's vendor's window in what EchelonGraph holds; null when the windows could not be read or carry none for this vendor."
+ }
+ },
+ "required": [
+ "vendor_window"
+ ],
+ "type": "object"
+ },
+ {
+ "type": "null"
+ }
+ ]
+ },
+ "error": {
+ "additionalProperties": false,
+ "properties": {
+ "kind": {
+ "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
+ "enum": [
+ "network",
+ "timeout",
+ "http",
+ "not_json",
+ "not_object",
+ "invalid_input",
+ "internal",
+ "unexpected_shape",
+ "radars"
+ ],
+ "type": "string"
+ },
+ "message": {
+ "description": "The cause: the API's own message, or what went wrong.",
+ "type": "string"
+ },
+ "path": {
+ "description": "The API path requested, when a request was made.",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "status": {
+ "anyOf": [
+ {
+ "maximum": 9007199254740991,
+ "minimum": -9007199254740991,
+ "type": "integer"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "The HTTP status, when the API answered one."
+ }
+ },
+ "required": [
+ "kind",
+ "path",
+ "status",
+ "message"
+ ],
+ "type": "object"
+ },
+ "freshness": {
+ "type": "null"
+ },
+ "measured_at": {
+ "type": "null"
+ },
+ "method": {
+ "type": "null"
+ },
+ "notes": {
+ "description": "Caveats, one sentence each.",
+ "items": {
+ "type": "string"
+ },
+ "type": "array"
+ },
+ "state": {
+ "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
+ "enum": [
+ "failed",
+ "invalid_input"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "state",
+ "measured_at",
+ "method",
+ "coverage",
+ "freshness",
+ "notes",
+ "error"
+ ],
+ "type": "object"
+ }
+]