addedInput schema / properties / cwe
Added value: +{
+ "description": "Exact CWE identifier, e.g. CWE-787, matched against every vulnerability entry in the advisory. A parent class does not match its children.",
+ "pattern": "^CWE-[0-9]+$",
+ "type": "string"
+}
addedInput schema / properties / inKev
Added value: +{
+ "description": "true selects advisories covering at least one CVE in the CISA Known Exploited Vulnerabilities catalog; false selects advisories covering none. Checked against every CVE an advisory covers, not only the twenty listed per result.",
+ "type": "boolean"
+}
changedInput schema / properties / product / description
Previous value: -"Case-insensitive substring of a product name."New value: +"Case-insensitive substring of a product name, matched literally — % and _ are ordinary characters."
changedInput schema / properties / q / description
Previous value: -"Full-text search over advisory titles, vendor names, and product names. Tokens are AND-combined; FTS5 operators in the input are neutralized rather than honored."New value: +"Full-text search over advisory titles, vendor names, and product names. Tokens are AND-combined; FTS5 operators in the input are neutralized rather than honored, and a token with no letter or digit is ignored. Needs at least one word or number."
changedInput schema / properties / vendor / description
Previous value: -"Case-insensitive substring of a vendor label. Vendor names are unnormalized upstream — the same company appears under several spellings — so this is substring, not exact."New value: +"Case-insensitive substring of a vendor label, matched literally — % and _ are ordinary characters. Vendor names are unnormalized upstream — the same company appears under several spellings — so this is substring, not exact."
changedOutput schema / properties / error / properties / data / properties / reason / description
Previous value: -"Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `invalid_cvss_range`: cvssMin exceeds cvssMax. `invalid_date_range`: A From bound is later than its matching To bound. `relevance_sort_without_query`: sortBy is relevance but no q was supplied, so there is no bm25 rank to sort by. Other values are possible when a failure originates below the handler."New value: +"Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `invalid_cvss_range`: cvssMin exceeds cvssMax. `invalid_date_range`: A From bound is later than its matching To bound. `relevance_sort_without_query`: sortBy is relevance but no q was supplied, so there is no bm25 rank to sort by. `empty_search_text`: q contains no word or number once quotes and punctuation are removed, so there is nothing to search for. `catalog_unavailable`: inKev is set, no KEV catalog snapshot is held, and the fetch from cisa.gov failed. Other values are possible when a failure originates below the handler."
changedOutput schema / properties / error / properties / data / properties / reason / examples
Previous value: -[
- "mirror_not_ready",
- "invalid_cvss_range",
- "invalid_date_range",
- "relevance_sort_without_query"
-]New value: +[
+ "mirror_not_ready",
+ "invalid_cvss_range",
+ "invalid_date_range",
+ "relevance_sort_without_query",
+ "empty_search_text",
+ "catalog_unavailable"
+]
changedOutput schema / properties / notice / description
Previous value: -"Guidance when nothing matched."New value: +"Guidance when nothing matched, when a page was capped, when KEV membership was not evaluated, or when a cwe result may be incomplete."
addedOutput schema / properties / results / items / properties / kevCves
Added value: +{
+ "description": "Every CVE this advisory covers that is in the KEV catalog, drawn from its full CVE list rather than the twenty in cves. Empty when none is; absent when KEV membership could not be evaluated.",
+ "items": {
+ "description": "One CVE identifier.",
+ "type": "string"
+ },
+ "type": "array"
+}