{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:36:13Z",
  "record_id": "VXI-EXT-OSV-API-01-v1",
  "record_kind": "external_reference",
  "title": "OSV: Known vulnerability queries",
  "system": "OSV.dev",
  "evidence_family": "vulnerability_intelligence",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Does an empty OSV query prove a package has no vulnerabilities?",
  "near_questions": [
    "What does an empty OSV result establish?",
    "Can OSV query a specific commit?",
    "How can an agent look up a package version?",
    "Does a batch query certify all dependencies?",
    "What if the package name or ecosystem is wrong?",
    "Which identifiers should accompany an OSV receipt?",
    "Does known-vulnerability coverage include undisclosed flaws?",
    "Can a query result establish runtime reachability?",
    "Why preserve the time of a vulnerability lookup?",
    "What additional evidence links a lookup to a deployed build?",
    "Does a clean database result make an artifact safe?",
    "How should missing vulnerability matches be described?"
  ],
  "supported_claims": [
    {
      "claim": "OSV provides queries for known vulnerabilities by package version or commit, including batches. No returned match does not prove absence of unknown issues or correct identification of the deployed artifact.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "absence of all vulnerabilities",
    "complete deployed dependency identification",
    "runtime exploitability"
  ],
  "public_summary": "OSV provides queries for known vulnerabilities by package version or commit, including batches. No returned match does not prove absence of unknown issues or correct identification of the deployed artifact.",
  "related_record_ids": [
    "VXI-EXT-OSV-API-03-v1",
    "VXI-EXT-OSV-API-04-v1",
    "VXI-EXT-OSV-06-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "OSV API 1.0",
    "source_url": "https://google.github.io/osv.dev/api/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-OSV-API-01-v1",
    "candidate_record_sha256": "f74d8d9f15aea0b6f7fbd62cd0c9ee4281ed506082178d9e27a57b3c8df4db1a",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "OSV provides queries for known vulnerabilities by package version or commit, including batches. No returned match does not prove absence of unknown issues or correct identification of the deployed artifact.",
    "required_buyer_context": "The package ecosystem, exact version or commit, query date and deployed artifact identity.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#osv-known-vulnerability-query",
  "machine_readable_record": "/varexis-index/records/osv-known-vulnerability-query.json"
}
