{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:36:13Z",
  "record_id": "VXI-EXT-OSV-06-v1",
  "record_kind": "external_reference",
  "title": "OSV-Scanner: Input coverage",
  "system": "OSV.dev",
  "evidence_family": "vulnerability_intelligence",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Does scanning a lockfile or SBOM establish complete deployment coverage?",
  "near_questions": [
    "Can OSV-Scanner inspect a software bill of materials?",
    "Which lockfile was used for a vulnerability scan?",
    "Does scanning a repository cover every deployed component?",
    "What if an SBOM omits a runtime dependency?",
    "How does scanner input affect the meaning of a clean result?",
    "Can an agent rely on an outdated inventory scan?",
    "What should a scan receipt identify about its input?",
    "Does directory scanning establish production coverage?",
    "How is the scanned artifact linked to the release?",
    "Can supported file formats imply complete analysis?",
    "Which dependencies were outside the submitted scan scope?",
    "What evidence is needed before claiming full scan coverage?"
  ],
  "supported_claims": [
    {
      "claim": "OSV-Scanner documents SBOM, lockfile and directory inputs. The result depends on what the supplied input represents; supported input formats do not establish a complete inventory of the running system.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "complete running-system inventory",
    "zero vulnerabilities",
    "all code paths assessed"
  ],
  "public_summary": "OSV-Scanner documents SBOM, lockfile and directory inputs. The result depends on what the supplied input represents; supported input formats do not establish a complete inventory of the running system.",
  "related_record_ids": [
    "VXI-EXT-OSV-API-01-v1",
    "VXI-EXT-OSV-API-03-v1",
    "VXI-EXT-OSV-API-04-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "OSV.dev",
    "source_url": "https://osv.dev/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-OSV-06-v1",
    "candidate_record_sha256": "a8ba3febf613ef4782da7d02b23ed2590f53cdffa4924b7cd921fda2f1fe7346",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "OSV-Scanner documents SBOM, lockfile and directory inputs. The result depends on what the supplied input represents; supported input formats do not establish a complete inventory of the running system.",
    "required_buyer_context": "The scanner version, input format, inventory scope, scan time and deployment mapping.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#osv-scanner-input-coverage",
  "machine_readable_record": "/varexis-index/records/osv-scanner-input-coverage.json"
}
