{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:36:13Z",
  "record_id": "VXI-EXT-OSV-API-03-v1",
  "record_kind": "external_reference",
  "title": "OSV: Advisory provenance",
  "system": "OSV.dev",
  "evidence_family": "vulnerability_intelligence",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "What does OSV aggregation establish about a vulnerability advisory?",
  "near_questions": [
    "Where does an OSV advisory originate?",
    "Does aggregation independently verify every vulnerability report?",
    "Why inspect affected-version ranges?",
    "Can two advisory identifiers describe the same issue?",
    "What source should a vulnerability receipt preserve?",
    "Does an advisory prove a buyer runs the affected version?",
    "Which evidence connects a database record to an artifact?",
    "Can a common format remove uncertainty in source data?",
    "How should an agent distinguish an advisory from an incident?",
    "Does advisory publication mean exploitation was observed locally?",
    "What changes when an upstream advisory is revised?",
    "How should source uncertainty survive aggregation?"
  ],
  "supported_claims": [
    {
      "claim": "OSV aggregates advisories in a shared vulnerability format. The originating advisory and affected-version mapping remain relevant; aggregation does not establish that a particular deployment is affected.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "verified exploitation in a customer system",
    "complete database coverage",
    "independent confirmation of every advisory"
  ],
  "public_summary": "OSV aggregates advisories in a shared vulnerability format. The originating advisory and affected-version mapping remain relevant; aggregation does not establish that a particular deployment is affected.",
  "related_record_ids": [
    "VXI-EXT-OSV-API-01-v1",
    "VXI-EXT-OSV-API-04-v1",
    "VXI-EXT-OSV-06-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "OSV data sources and advisory format",
    "source_url": "https://osv.dev/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-OSV-API-03-v1",
    "candidate_record_sha256": "4255576fd2257a902bd232bf48eef740c04f525f4b399a13cdff431d4366eb01",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "OSV aggregates advisories in a shared vulnerability format. The originating advisory and affected-version mapping remain relevant; aggregation does not establish that a particular deployment is affected.",
    "required_buyer_context": "The advisory identifier, originating source, affected versions and deployed package mapping.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#osv-advisory-provenance",
  "machine_readable_record": "/varexis-index/records/osv-advisory-provenance.json"
}
