Skip to content

Freshness and ingest ​

How far behind the upstream sources this database runs, measured rather than promised, and where the NVD ingestion stands. Neither route says anything about a CVE; both say whether the answer you are about to read rests on current data.

GET /api/v1/freshness
GET /api/v1/nvd/status

For the composite view that also names which checks could not be made and whether an answer can be acted on, see service status.

Ingest latency per source ​

GET /api/v1/freshness

Latency runs from a record's publication date to the moment this service first stored it, reported per source. The tails differ in kind: GitHub republishes historical advisories and the NixOS security review waits on human adjudication, so a blended figure would describe none of them. Where a record carries an upstream availability time the latency is split into the publisher's share and ours.

json
{
  "success": true,
  "data": {
    "computedAt": "2026-09-28T00:30:12.104Z",
    "sampleMonth": "2026-09",
    "sampleSize": 4120,
    "windowMinutes": 30,
    "unmeasurable": 37,
    "seenBeforePublished": 12,
    "sources": {
      "cve-list-v5": {
        "count": 3030,
        "p50Minutes": 25.1,
        "p90Minutes": 61.1,
        "p99Minutes": 1321,
        "maxMinutes": 20160,
        "withinThirtyMinutes": 1866,
        "withinThirtyMinutesPct": 61.6,
        "upstreamP50Minutes": 11.4,
        "ourP50Minutes": 13.7,
        "decomposed": 2811
      }
    },
    "note": "Records never indexed do not appear; this measures latency, not coverage."
  }
}
FieldMeaning
sampleMonth, sampleSizeThe month of records measured and how many.
unmeasurableRecords lacking a publication or first-seen time.
seenBeforePublishedRecords stored before their published date, which CNAs revise after the fact.
sources.<id>.p50Minutes, p90Minutes, p99Minutes, maxMinutesPercentiles of the latency, or null when the source has too few records.
sources.<id>.withinThirtyMinutesPctThe share of records stored within the window.
sources.<id>.upstreamP50Minutes, ourP50Minutes, decomposedThe split between the publisher's delay and ours, and how many records carried enough to split.

Records that were never indexed do not appear, so this measures latency and not coverage. 503 means no measurement exists yet, which is not a measurement of zero.

NVD ingestion ​

GET /api/v1/nvd/status

The operational state of this API's NVD ingestion: the historical backfill and the incremental sync that follows it. This is a statement about this deployment, not about NVD.

json
{
  "success": true,
  "data": {
    "backfill": {
      "currentChunk": { "start": "2026-08-18T21:31:13.758Z", "end": "2026-09-03T21:31:13.758Z" },
      "targetEndDate": "2026-09-03T21:31:13.758Z",
      "chunkProgress": "10000/11867",
      "chunksCompleted": 7,
      "complete": true,
      "totalProcessed": 371071,
      "lastRun": "2026-09-07T21:31:40.781Z"
    },
    "sync": {
      "lastSync": "2026-09-28T01:01:37.919Z",
      "lastResult": { "processed": 0, "stored": 0, "updated": 0 }
    }
  },
  "timestamp": "2026-09-28T01:03:27.924Z"
}

backfill.complete: false means historical chunks are still being walked, so counts derived from NVD data are still growing. Before the first run either block reads { "status": "not_started" }.