One dossier per CVE
Canonical description, severity, affected packages, fixed versions and typed references in a single JSON document.
One record per CVE from MITRE, NVD, OSV, GitHub Advisories, EPSS, CISA KEV and nixpkgs security issues, stating which sources answered and what is still missing.