Freshness and ingest
How far behind the upstream sources this database runs, measured rather than promised, and where the NVD ingestion stands. Neither route says anything about a CVE; both say whether the answer you are about to read rests on current data.
GET /api/v1/freshness
GET /api/v1/nvd/statusFor the composite view that also names which checks could not be made and whether an answer can be acted on, see service status.
Ingest latency per source
GET /api/v1/freshnessLatency runs from a record's publication date to the moment this service first stored it, reported per source. The tails differ in kind: GitHub republishes historical advisories and the NixOS security review waits on human adjudication, so a blended figure would describe none of them. Where a record carries an upstream availability time the latency is split into the publisher's share and ours.
{
"success": true,
"data": {
"computedAt": "2026-09-28T00:30:12.104Z",
"sampleMonth": "2026-09",
"sampleSize": 4120,
"windowMinutes": 30,
"unmeasurable": 37,
"seenBeforePublished": 12,
"sources": {
"cve-list-v5": {
"count": 3030,
"p50Minutes": 25.1,
"p90Minutes": 61.1,
"p99Minutes": 1321,
"maxMinutes": 20160,
"withinThirtyMinutes": 1866,
"withinThirtyMinutesPct": 61.6,
"upstreamP50Minutes": 11.4,
"ourP50Minutes": 13.7,
"decomposed": 2811
}
},
"note": "Records never indexed do not appear; this measures latency, not coverage."
}
}| Field | Meaning |
|---|---|
sampleMonth, sampleSize | The month of records measured and how many. |
unmeasurable | Records lacking a publication or first-seen time. |
seenBeforePublished | Records stored before their published date, which CNAs revise after the fact. |
sources.<id>.p50Minutes, p90Minutes, p99Minutes, maxMinutes | Percentiles of the latency, or null when the source has too few records. |
sources.<id>.withinThirtyMinutesPct | The share of records stored within the window. |
sources.<id>.upstreamP50Minutes, ourP50Minutes, decomposed | The split between the publisher's delay and ours, and how many records carried enough to split. |
Records that were never indexed do not appear, so this measures latency and not coverage. 503 means no measurement exists yet, which is not a measurement of zero.
NVD ingestion
GET /api/v1/nvd/statusThe operational state of this API's NVD ingestion: the historical backfill and the incremental sync that follows it. This is a statement about this deployment, not about NVD.
{
"success": true,
"data": {
"backfill": {
"currentChunk": { "start": "2026-08-18T21:31:13.758Z", "end": "2026-09-03T21:31:13.758Z" },
"targetEndDate": "2026-09-03T21:31:13.758Z",
"chunkProgress": "10000/11867",
"chunksCompleted": 7,
"complete": true,
"totalProcessed": 371071,
"lastRun": "2026-09-07T21:31:40.781Z"
},
"sync": {
"lastSync": "2026-09-28T01:01:37.919Z",
"lastResult": { "processed": 0, "stored": 0, "updated": 0 }
}
},
"timestamp": "2026-09-28T01:03:27.924Z"
}backfill.complete: false means historical chunks are still being walked, so counts derived from NVD data are still growing. Before the first run either block reads { "status": "not_started" }.