removedInput schema / properties / ecosystem / minLength
Removed value: -1
removedInput schema / properties / name / minLength
Removed value: -1
removedInput schema / properties / version / minLength
Removed value: -1
changedOutput schema / properties / vulns / items / properties / affectedRanges / items / properties / fixed / description
Previous value: -"First safe version — the version to upgrade to (convenience view — see events[])."New value: +"The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[])."
changedOutput schema / properties / vulns / items / properties / fixedVersions / description
Previous value: -"First safe version(s) per affected package entry. Empty if no fix exists yet."New value: +"Every fixed version the advisory lists for the queried package, in record order. A multi-interval range contributes one per interval (typically one per release line); affectedRanges shows which interval each one closes. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."
changedOutput schema / properties / vulns / items / properties / fixedVersions / items / description
Previous value: -"A first-safe version string."New value: +"A version that fixes the vulnerability for the queried package."
changedOutput schema / properties / vulns / items / properties / severity / description
Previous value: -"CVSS severity entries. May be empty for advisories not yet scored."New value: +"Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for advisories not yet scored and for advisories that score each affected package separately — severitySource then carries the queried package entry used."
changedOutput schema / properties / vulns / items / properties / severity / items / description
Previous value: -"One CVSS severity entry."New value: +"One record-level severity entry."
changedOutput schema / properties / vulns / items / properties / severity / items / properties / score / description
Previous value: -"CVSS vector string (e.g. \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\")."New value: +"CVSS vector string (e.g. \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\"), or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
changedOutput schema / properties / vulns / items / properties / severity / items / properties / type / description
Previous value: -"CVSS version: \"CVSS_V3\", \"CVSS_V4\", or \"CVSS_V2\"."New value: +"Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
changedOutput schema / properties / vulns / items / properties / severityLabel / description
Previous value: -"Human-readable severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\"). Present on GHSA-sourced records; null otherwise."New value: +"Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses the queried package's affected-level severity entries when the record-level list is empty. Null when no source yields a label."
addedOutput schema / properties / vulns / items / properties / severitySource
Added value: +{
+ "anyOf": [
+ {
+ "additionalProperties": false,
+ "properties": {
+ "computedScore": {
+ "description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
+ "type": "number"
+ },
+ "score": {
+ "description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.",
+ "type": "string"
+ },
+ "type": {
+ "description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.",
+ "enum": [
+ "database_specific",
+ "Ubuntu",
+ "CVSS_V3",
+ "CVSS_V4"
+ ],
+ "type": "string"
+ }
+ },
+ "required": [
+ "type",
+ "score"
+ ],
+ "type": "object"
+ },
+ {
+ "type": "null"
+ }
+ ],
+ "description": "The severity entry severityLabel was derived from. Null exactly when the label is."
+}
changedOutput schema / properties / vulns / items / required
Previous value: -[
- "id",
- "summary",
- "aliases",
- "severity",
- "severityLabel",
- "fixedVersions",
- "affectedRanges",
- "cweIds",
- "published",
- "modified"
-]New value: +[
+ "id",
+ "summary",
+ "aliases",
+ "severity",
+ "severityLabel",
+ "severitySource",
+ "fixedVersions",
+ "affectedRanges",
+ "cweIds",
+ "published",
+ "modified"
+]