{
  "schema": "varexis-index-advisory-api/1",
  "endpoint": "/api/index/advisories",
  "method": "GET",
  "authentication": false,
  "dataset": "/varexis-index/advisory-dataset.json",
  "examples": [
    {
      "advisory_id": "GHSA-jfh8-c2jp-5v3q"
    },
    {
      "ecosystem": "npm",
      "package": "lodash"
    },
    {
      "record_id": "A returned VXI-OSV record_id",
      "version": "Optional exact version string"
    }
  ],
  "selection": "Supply advisory_id OR both ecosystem and package. Advisory IDs match declared aliases too. Package and ecosystem spelling are exact and case-sensitive. record_id selects one complete source projection.",
  "pagination": "At most 20 summaries. Pass next_cursor as cursor with exactly the same search arguments. A null cursor means that search is exhausted, not that the package is safe.",
  "response": "Search returns source status, modification time, record and route IDs, content hashes, preview URLs and purchase URLs. record_id returns the full free version-bound preview; per-record uncompressed content is capped at 2 MB.",
  "versions": "With record_id only, optional version performs exact string membership in the source's explicit versions. Missing matches are UNRESOLVED_NOT_LISTED_IS_NOT_SAFE; ranges and ecosystem version ordering are not evaluated. Withdrawal takes precedence over membership.",
  "freshness": "Frozen 8 October 2026 source capture, not a live OSV query. Check current upstream advisories before reliance.",
  "exclusions": [
    "12 staged quarantined records",
    "Exploitability and deployment assessment",
    "Automatic version-range interpretation",
    "Fresh source acquisition or independent verification"
  ],
  "paid_retrieval": "Pass a returned route_id to /api/index/preview and then the existing checkout/result flow, or open its purchase_url. When checking a version through REST, include exactly the same version in preview and checkout. Existing subscriptions may save it through /api/index/query. Payment saves one record; it does not buy the whole corpus or make a security finding.",
  "errors": {
    "400": "Invalid or mixed selectors, unknown fields, unsupported ecosystem, invalid cursor",
    "422": "Unknown or unavailable record; no payment",
    "503": "Source or database unavailable; do not interpret as no evidence",
    "429": "Public lookup rate exceeded; retry after 60 seconds."
  },
  "attribution": "/varexis-index/advisory-attribution.json",
  "mcp": {
    "url": "/mcp",
    "lookup_tool": "find_package_advisories",
    "preview_tool": "preview_evidence_answer"
  },
  "rate_limit": "60 public database lookups per minute per source IP across REST and MCP. Retry after 60 seconds on RETRY_LATER."
}
