{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:36:13Z",
  "record_id": "VXI-EXT-OSV-API-04-v1",
  "record_kind": "external_reference",
  "title": "OSV: Import quality findings",
  "system": "OSV.dev",
  "evidence_family": "vulnerability_intelligence",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Are OSV import findings accepted vulnerability results?",
  "near_questions": [
    "What does an OSV import finding mean?",
    "Is an import-quality failure a confirmed vulnerability?",
    "Why preserve the experimental endpoint label?",
    "Can an ingestion issue be counted as an accepted advisory?",
    "What evidence separates bad input from an affected package?",
    "Should an agent recheck an experimental OSV interface?",
    "Can rejected records justify a customer security claim?",
    "How should a receipt label import-time quality findings?",
    "Does a successful download mean a record was accepted?",
    "What additional review is needed after an import finding?",
    "Can an experimental response be assumed stable?",
    "Which source record explains a vulnerability ingestion issue?"
  ],
  "supported_claims": [
    {
      "claim": "OSV documents an experimental endpoint for records that fail import-time quality checks. Such findings describe ingestion issues and must not be treated as accepted vulnerability results or a stable interface guarantee.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "accepted advisory status",
    "stable experimental API contract",
    "vulnerability proven by an import failure"
  ],
  "public_summary": "OSV documents an experimental endpoint for records that fail import-time quality checks. Such findings describe ingestion issues and must not be treated as accepted vulnerability results or a stable interface guarantee.",
  "related_record_ids": [
    "VXI-EXT-OSV-API-01-v1",
    "VXI-EXT-OSV-API-03-v1",
    "VXI-EXT-OSV-06-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "OSV API 1.0",
    "source_url": "https://google.github.io/osv.dev/api/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-OSV-API-04-v1",
    "candidate_record_sha256": "583b8fdbaa2feb283c5e7ffcd3974f8dc75de1752fcdf39e8a3a7059841ef8e7",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "OSV documents an experimental endpoint for records that fail import-time quality checks. Such findings describe ingestion issues and must not be treated as accepted vulnerability results or a stable interface guarantee.",
    "required_buyer_context": "The source record, failed quality check and current experimental endpoint documentation.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#osv-import-quality-boundary",
  "machine_readable_record": "/varexis-index/records/osv-import-quality-boundary.json"
}
