Data Sources
Vulnpatch aggregates security data from multiple authoritative sources to provide comprehensive vulnerability information. Each source is relayed under its own terms, stated source by source on the data terms page together with Vulnpatch's own licence (CC BY 4.0) and the citation format. An incorrect record goes through data corrections.
Primary Sources
nixpkgs security issues
The primary nixpkgs source is the set of GitHub issues in NixOS/nixpkgs labelled 1.severity: security, open and closed. Most are filed automatically for CVEs that match a Nix package; some are filed by people. Vulnpatch reads them by label, so issues from any author are included.
The NixOS security review also supplies automatic suggestions and their accepted, published, or rejected decisions. A rejected suggestion may contain many proposed attributes; rejecting it does not mean every listed attribute was separately inspected. Vulnpatch also derives package-name candidates from Repology and the nixpkgs search index. Those are discovery leads, not confirmed affected packages. The dossier's nixpkgs.candidates[].identity records whether project identity was corroborated or the result is only a name match. See the dossier's security review fields.
Data provided:
- CVE identifiers
- Affected packages
- Severity levels (critical, high, medium, low)
- Fix availability status
- Assignment status
OSV.dev
OSV (Open Source Vulnerabilities) is Google's distributed vulnerability database for open source software.
Data provided:
- Vulnerability details across 38+ ecosystems
- Affected version ranges
- References and advisories
- Severity scores
Repology
Repology tracks package versions across hundreds of repositories.
Data provided:
- Current package versions
- Version history
- Cross-repository comparisons
- Upstream release information
Secondary Sources
CVE Database
The CVE Project provides the authoritative CVE identifier assignments.
GitHub Advisories
GitHub Security Advisories provides vulnerability information for packages hosted on GitHub.
NVD (National Vulnerability Database)
NVD provides additional analysis and CVSS scores for CVEs.
Data Freshness
| Source | Update Frequency |
|---|---|
| nixpkgs security issues | Changed issues every 30 minutes; a full re-read daily |
| OSV.dev | Hourly |
| Repology | Hourly |
| NVD | Daily |
Data Quality
Vulnpatch applies several quality measures:
- Deduplication: CVEs appearing in multiple sources are merged
- Severity normalization: CVSS scores are normalized to critical/high/medium/low
- Version matching: Affected versions are validated against Repology data
- Confidence scoring: Matches include confidence levels based on data quality
Terms and corrections
Every source above is relayed under its own terms, and the API carries them with the data: a dossier's provenance names the licence behind each fact and its terms block carries the citation and the notices. The data terms page holds the table. A record that looks wrong is reported through data corrections, which says which upstream owns which field.