Skip to content

Data Terms ​

Vulnpatch relays other people's records and adds a layer of its own. This page states the terms of both, source by source, so a reader deciding what they may republish does not have to guess. The same terms travel inside every API response: a dossier's provenance names the licence behind each fact, its terms block carries the citation and the notices, and GET /api/v1/sources lists every source with its licence.

Vulnpatch's own layer ​

Vulnpatch's compilation, its derived fields (nixpkgs, quality, agentHints, channel status, fix timing, evidence tags) and the nixpkgs OSV feed are licensed CC BY 4.0. Each upstream record keeps its own terms, named in provenance. Attribution to Vulnpatch is satisfied by the citation below.

CC BY is the licence, not CC0 and not ShareAlike. Rights Vulnpatch does not hold cannot be waived, so a public-domain dedication would claim more than Vulnpatch has; and the inputs include terms that a ShareAlike condition could not absorb. The published layer is Vulnpatch's; the records inside it are their publishers'.

Terms by source ​

SourceTerms as publishedAttributionLimits
CVE Program (MITRE)CVE Terms of Use: a perpetual, worldwide, irrevocable licence to reproduce, prepare derivative works of, sublicense and distribute CVE, provided that every copy reproduces MITRE's copyright designation and the licence itself.Required: the copyright designation and the licence, in every copy. Both are carried in provenance and in terms.notices.None.
MITRE CWECWE Terms of Use: free for research, development and commercial use under a non-exclusive, royalty-free licence.Required: reproduce MITRE's copyright designation and licence. Vulnpatch shows both in the footer and carries them with each API definition.Definitions are retained in KV without expiry. Each graph verifies the current catalogue version and refreshes requested definitions when it changes.
NVDNVD API terms of use. A work of the US government, in the public domain. Services using the API are asked to display this notice prominently: "This product uses the NVD API but is not endorsed or certified by the NVD."Requested; Vulnpatch treats it as required and shows it in every footer.Modified NVD content may not be attributed to NVD. A severity Vulnpatch normalises is Vulnpatch's; the raw NVD score stays beside it.
ENISA EUVDENISA legal notice authorizes reproduction of ENISA website material with source acknowledgment unless stated otherwise. EUVD combines third-party records whose rights may differ; no blanket licence is asserted for the aggregated data.Required: name ENISA and link the EUVD record. The dossier provenance carries both.EUVD identifiers, reported products and advisory links are kept separate from canonical CVE facts. Raw backfill snapshots and revisions are held in a private operational archive, not exposed as a public bulk feed. ENISA's notice does not grant rights in third-party material.
CISA KEVCC0 1.0.Optional. Vulnpatch names CISA anyway.Use of the data is not use of the CISA logo or the DHS seal, and is not an endorsement.
GitHub Advisory DatabaseCC BY 4.0.Required: credit GitHub, link the licence, say whether the record was changed and link the record where practicable.None.
OSV.devNo licence of its own; each record carries its source's licence. GHSA, PyPI, Go, OSS-Fuzz, PSF and Erlang records are CC BY 4.0; RustSec, GSD, Haskell and opam are CC0; others are MIT, BSD or Apache 2.0; Ubuntu records are CC BY-SA 4.0.Per record. Read the record's source.Ubuntu records are ShareAlike. Vulnpatch relays them unchanged and never rewrites one into its own fields, which is what would trigger the condition.
FIRST EPSSEPSS usage agreement: scores are granted freely to the public; attribution is requested.Requested; Vulnpatch treats it as required. The supplied form is "See EPSS at https://www.first.org/epss".None.
RepologyThe API page states a request rate and asks bulk clients to identify themselves. No licence is stated for the data.Unknown, so treated as required.Vulnpatch uses Repology to match package names and links to the project page. It does not redistribute Repology tables.
nixpkgsMIT, copyright 2003-2026 Eelco Dolstra and the Nixpkgs/NixOS contributors.Required where a Nix expression or a patch is reproduced. Attribute names, versions and channel facts are not expression.None.
nixpkgs security issues (GitHub)GitHub's terms of service let other users view public content through GitHub and leave public repositories open to lawful use. They grant no licence to republish issue bodies elsewhere. A person's comment is their own copyright.Link to the issue.Facts and links only; see below.

Where terms have not been confirmed the API reports the licence as unknown and attribution as required. Guessing in the permissive direction is the expensive mistake, because someone relies on it.

Two sources carry text Vulnpatch has no licence to republish: Repology's tables and the bodies of nixpkgs security issues and their comments. For both, the rule is the same. Vulnpatch relays facts (an issue's title, state, labels, attribute names, dates and CVE ids; a package's name and the versions Repology reports) and links to the page they came from. It does not republish comment bodies or Repology's tables, and it does not paraphrase either into its own fields. Bot-filed issues consist mostly of CVE text, which the CVE terms already cover, plus facts.

The CC BY 4.0 claim over Vulnpatch's layer rests on this rule. A dossier that carried a comment body or a Repology table would be claiming a licence Vulnpatch cannot grant.

Where the terms appear ​

  • Every provenance entry on a dossier carries license, licenseUrl, attributionRequired, attribution (the notice to carry) and termsUrl.
  • Every dossier carries a terms block: vulnpatch (the licence over the layer), citation and notices, one per present source.
  • The nixpkgs OSV feed envelope carries license and terms, and each record carries database_specific.vulnpatch.terms, so a record copied out of the feed keeps them.
  • GET /api/v1/sources lists every source with the same fields.
  • The footer of every page on cve.vulnpatch.dev, vulnpatch.dev and this site shows the NVD notice and the MITRE CWE attribution. ENISA requires source acknowledgment, not a permanent footer notice; the EUVD record and dossier provenance name ENISA, and this page explains its reuse terms.

Citing Vulnpatch ​

For a reader:

Ad Astra Computing. Vulnpatch CVE dossier for CVE-2026-1234, assessment asmt_.... https://cve.vulnpatch.dev/CVE-2026-1234. Retrieved 2026-09-27. Data: CVE Program (MITRE), NVD, CISA KEV, GitHub Advisory Database (CC BY 4.0), FIRST EPSS, nixpkgs.

For a program, terms.citation on every dossier:

json
{
  "text": "Ad Astra Computing. Vulnpatch CVE dossier for CVE-2026-1234, assessment asmt_.... https://cve.vulnpatch.dev/CVE-2026-1234. Data: CVE Program (MITRE), NVD, GitHub Advisory Database (CC BY 4.0).",
  "url": "https://cve.vulnpatch.dev/CVE-2026-1234",
  "assessmentId": "asmt_...",
  "retrieved": "2026-09-27T12:00:00Z",
  "license": "CC-BY-4.0"
}

The assessment id changes whenever the inputs change, which is what makes the citation reproducible. retrieved is stamped when the copy is served, not when the document was built, so it is the time to quote; the text field leaves it out because the same cached document is served to many readers.

The feed's envelope carries the same shape under terms.citation, with modified in place of the assessment id.

Reporting an incorrect record ​

Terms say who owns a record; they do not make it right. The data corrections page says which upstream owns which field and how to reach Vulnpatch about its own. A vulnerability in the service itself is a different matter, covered by the vulnerability disclosure policy.