{
  "schema": "varexis-index-advisory-attribution/1",
  "checked_on": "2026-10-08",
  "source_directory": "https://google.github.io/osv.dev/data/",
  "aggregation": "OSV ecosystem exports; original advisory publishers retain attribution. VAREXIS is not the author of upstream vulnerability findings.",
  "changes": "One affected-package object is projected from each source advisory. Narrative details are omitted; aliases, version conditions, source hashes, dates, references and credits are retained. VAREXIS adds retrieval metadata and explicit limitations.",
  "licences": {
    "Apache-2.0": "https://varexis.tech/varexis-index/licences/Apache-2.0.txt",
    "CC-BY-4.0": "https://creativecommons.org/licenses/by/4.0/",
    "CC0-1.0": "https://creativecommons.org/publicdomain/zero/1.0/"
  },
  "publishers": [
    {
      "id": "MAL",
      "attribution": "OpenSSF Malicious Packages contributors",
      "licence": "Apache-2.0",
      "source": "https://github.com/ossf/malicious-packages",
      "licence_source": "https://github.com/ossf/malicious-packages/blob/main/LICENSE"
    },
    {
      "id": "GHSA",
      "attribution": "GitHub Advisory Database contributors",
      "licence": "CC-BY-4.0",
      "source": "https://github.com/github/advisory-database",
      "licence_source": "https://github.com/github/advisory-database/blob/main/LICENSE.md"
    },
    {
      "id": "PYSEC",
      "attribution": "PyPA Advisory Database contributors",
      "licence": "CC-BY-4.0",
      "source": "https://github.com/pypa/advisory-database",
      "licence_source": "https://github.com/pypa/advisory-database/blob/main/LICENSE"
    },
    {
      "id": "GO",
      "attribution": "Go Vulnerability Database contributors",
      "licence": "CC-BY-4.0",
      "source": "https://vuln.go.dev",
      "licence_source": "https://github.com/golang/vulndb#license"
    },
    {
      "id": "RUSTSEC",
      "attribution": "RustSec Advisory Database contributors",
      "licence": "CC0-1.0",
      "source": "https://github.com/rustsec/advisory-db",
      "licence_source": "https://github.com/rustsec/advisory-db/blob/main/LICENSE.txt"
    },
    {
      "id": "OSV",
      "attribution": "OSS-Fuzz contributors",
      "licence": "CC-BY-4.0",
      "source": "https://github.com/google/oss-fuzz-vulns",
      "licence_source": "https://github.com/google/oss-fuzz-vulns/blob/main/LICENSE"
    },
    {
      "id": "EEF",
      "attribution": "Erlang Ecosystem Foundation CNA and credited contributors",
      "licence": "CC-BY-4.0",
      "source": "https://cna.erlef.org",
      "licence_source": "https://cna.erlef.org/data-licensing/"
    }
  ],
  "notices": "OpenSSF Malicious Packages root was checked for a NOTICE file on 2026-10-08; none was present. Individual source credits are retained. No publisher endorsement is implied.",
  "reuse": "Public upstream terms continue to apply to advisory data. VAREXIS paid delivery does not impose an exclusive right over that data."
}