changedInput schema / properties / id / description
Previous value: -"OSV vulnerability ID. Accepts any prefix: \"GHSA-\" (GitHub), \"PYSEC-\" (Python), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"CVE-\" (fallback direct lookups). Example: \"GHSA-29mw-wpgm-hmr9\"."New value: +"One exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include \"GHSA-\" (GitHub), \"PYSEC-\" (PyPI), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"USN-\" (Ubuntu), \"RHSA-\" (Red Hat), and \"CVE-\". No wildcards or partial IDs — take IDs from osv_query_package or osv_query_batch results. Example: \"GHSA-29mw-wpgm-hmr9\"."
removedInput schema / properties / id / minLength
Removed value: -1
changedInput schema / properties / id / pattern
Previous value: -"\\S"New value: +"^[A-Za-z][A-Za-z0-9_]*-\\S(.*\\S)?$"
changedOutput schema / anyOf
Previous value: -[
- {
- "not": {
- "required": [
- "error"
- ]
- },
- "required": [
- "id",
- "summary",
- "details",
- "aliases",
- "published",
- "modified",
- "severity",
- "severityLabel",
- "affected",
- "cweIds",
- "references",
- "schemaVersion"
- ]
- },
- {
- "required": [
- "error"
- ]
- }
-]New value: +[
+ {
+ "not": {
+ "required": [
+ "error"
+ ]
+ },
+ "required": [
+ "id",
+ "summary",
+ "details",
+ "aliases",
+ "published",
+ "modified",
+ "severity",
+ "severityLabel",
+ "severitySource",
+ "affected",
+ "cweIds",
+ "references",
+ "schemaVersion"
+ ]
+ },
+ {
+ "required": [
+ "error"
+ ]
+ }
+]
changedOutput schema / properties / affected / items / properties / ranges / items / properties / fixed / description
Previous value: -"First safe version (convenience view — the last \"fixed\" event; see events[])."New value: +"The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[])."
addedOutput schema / properties / affected / items / properties / severity
Added value: +{
+ "description": "Severity entries scoped to this package. Present only when the advisory scores packages separately; the record-level severity is then empty.",
+ "items": {
+ "additionalProperties": false,
+ "description": "One package-level severity entry.",
+ "properties": {
+ "score": {
+ "description": "CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\".",
+ "type": "string"
+ },
+ "type": {
+ "description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\".",
+ "type": "string"
+ }
+ },
+ "required": [
+ "type",
+ "score"
+ ],
+ "type": "object"
+ },
+ "type": "array"
+}
changedOutput schema / properties / severity / description
Previous value: -"CVSS severity entries. Empty for unscored advisories."New value: +"Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately."
changedOutput schema / properties / severity / items / description
Previous value: -"One CVSS severity entry."New value: +"One record-level severity entry."
changedOutput schema / properties / severity / items / properties / score / description
Previous value: -"CVSS vector string."New value: +"CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
changedOutput schema / properties / severity / items / properties / type / description
Previous value: -"CVSS version: \"CVSS_V3\", \"CVSS_V4\", or \"CVSS_V2\"."New value: +"Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
changedOutput schema / properties / severityLabel / description
Previous value: -"Human-readable severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\"). Present on GHSA-sourced records; null when not available."New value: +"Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label."
addedOutput schema / properties / severitySource
Added value: +{
+ "anyOf": [
+ {
+ "additionalProperties": false,
+ "properties": {
+ "computedScore": {
+ "description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
+ "type": "number"
+ },
+ "score": {
+ "description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.",
+ "enum": [
+ "database_specific",
+ "Ubuntu",
+ "CVSS_V3",
+ "CVSS_V4"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type",
+ "score"
+ ],
+ "type": "object"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "The severity entry severityLabel was derived from. Null exactly when the label is."
+}