)]}'
{
  "log": [
    {
      "commit": "5b96a28fbab7533bfbb28078303180f25800ad0c",
      "tree": "c0ddbc2dc0bb2a20b4e232e95d5ecf2c7df2dbdd",
      "parents": [
        "44e8c1ba26327cd910e8a6f150e0a85e7b9c9ce1"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Tue Oct 06 15:14:33 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Oct 06 15:14:33 2026 +0200"
      },
      "message": "fix: keep bearer-token authentication to the request (#269)\n\nA bearer token authenticates one request. ensureAuthenticated also\nstored the resolved user in the session, which asfinit() reads on later\nrequests; set only req.user instead.\n\nGenerated-by: Claude Opus 5"
    },
    {
      "commit": "44e8c1ba26327cd910e8a6f150e0a85e7b9c9ce1",
      "tree": "e5b141fd421d82beca65f6807d94adbbef46904c",
      "parents": [
        "6a86e459a1f33256655c57ead38314e0c85ea5cd"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Tue Oct 06 13:57:57 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Oct 06 13:57:57 2026 +0200"
      },
      "message": "feat(cve5): show the repository when set and require a GitBox URL (#271)\n\nThe `repo` field of an affected product was always hidden, so a record\nthat carried one gave no way to see or correct it. Show it, like the\nlegacy package identifiers, only when it has a value.\n\nThe schema describes `repo` as the place to resolve git hash version\nranges, so it must be cloneable. Require the one canonical form,\nhttps://gitbox.apache.org/repos/asf/\u003cname\u003e.git, with the .git suffix\nas in the git.kernel.org URLs the Linux CNA publishes. The URL is\nparsed rather than matched by prefix, so a look-alike host or http:\ndoes not pass. Nothing may follow the name: git appends its own path,\nso the gitweb form (?p\u003d\u003cname\u003e.git) or a deeper path does not clone.\n\nThe check lives in custom/cve5/script.js, since validators reach the\npage as source text and can only call browser globals.\n\nAssisted-By: Claude Opus 5.5 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "6a86e459a1f33256655c57ead38314e0c85ea5cd",
      "tree": "33d83f901b3e4b0b80593c29a50eaf97c7231f81",
      "parents": [
        "0eaee4ccd977966e22669994aa976e064dfcf9cb"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Tue Oct 06 10:17:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Oct 06 10:17:29 2026 +0200"
      },
      "message": "fix: name each product once in the published title (#270)\n\nWhen a CVE record lists the same product more than once, the title\nprefix repeated it (e.g. \"Alpha, Beta, Alpha: ...\"). The editor\u0027s copy\nof getProductListNoVendor already skipped duplicates, but the copy used\nby customRoutes/publishcve.js did not.\n\nMove the single implementation to custom/cve5/script.js, which is both\ninlined into the editor page and loadable in Node, and require it from\npublishcve.js and the unit tests instead of duplicating it.\n\nAssisted-By: Claude Opus 5.5 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "0eaee4ccd977966e22669994aa976e064dfcf9cb",
      "tree": "003a6fdaf9f5d7300a3e1283998f226f4ea740e9",
      "parents": [
        "cfb2b48b5aa0f15a38085e3334c99c6c22ce6f46"
      ],
      "author": {
        "name": "Sebb",
        "email": "sebbASF@users.noreply.github.com",
        "time": "Mon Oct 05 19:56:20 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Oct 05 20:56:20 2026 +0200"
      },
      "message": "Drop advisory URL from subject (#267)\n\nThe subject is confusing when the advisory URL is included."
    },
    {
      "commit": "cfb2b48b5aa0f15a38085e3334c99c6c22ce6f46",
      "tree": "7cf88e1b57eb2de24b825b054d5f91a7ba62d9d8",
      "parents": [
        "9ffa163d709c23ee63cf90dcd1b9058235cf8ca3"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Mon Oct 05 19:09:28 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Oct 05 19:09:28 2026 +0200"
      },
      "message": "fix: treat an unset NODE_ENV as development (#268)\n\n* fix: treat an unset NODE_ENV as development\n\nconfig/conf.js says production mode is opt-in, with unset treated as\nnon-production, but app.js set NODE_ENV to production before loading the\nconfig whenever it was unset. A local `node app.js` without NODE_ENV\ntherefore allocated real CVEs through CVE Services and sent email.\n\nDrop the default so production needs NODE_ENV\u003dproduction, as the\nsystemd unit in scripts/vulnogram.service already sets, and print a\nDEVELOPMENT MODE banner otherwise so the mode is visible at startup.\n\nGenerated-by: Claude Opus 5\n\n* fix: set NODE_ENV\u003dproduction in the production service unit\n\nThe production instance did not set NODE_ENV and relied on the default\nremoved in the previous commit; without it, it would come up in\ndevelopment mode.\n\nGenerated-by: Claude Opus 5\n\n* docs: document development and production mode\n\nGenerated-by: Claude Opus 5\n\n* fix: run the test instance in development mode explicitly\n\nSet NODE_ENV\u003ddevelopment in the test service unit, so the test instance\nnever allocates real CVEs or sends email, and say so in README-ASF.md.\n\nGenerated-by: Claude Opus 5"
    },
    {
      "commit": "9ffa163d709c23ee63cf90dcd1b9058235cf8ca3",
      "tree": "e929b214ab84421ca416d9bca759f520eb11bd11",
      "parents": [
        "8b0f14707e6d9d907710a9e692e30a4cab98af29",
        "86e258a1549d196ae6bf9fcc7fea5a1fc55e78ff"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Oct 05 17:41:28 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Oct 05 17:41:28 2026 +0200"
      },
      "message": "Merge pull request #264 from potiuk/token-authorize\n\nfeat(token): let tools request a PMC-scoped token through the browser"
    },
    {
      "commit": "86e258a1549d196ae6bf9fcc7fea5a1fc55e78ff",
      "tree": "e929b214ab84421ca416d9bca759f520eb11bd11",
      "parents": [
        "73ec7edd52fcb3eefae10e8fa80f42d2a70593e2"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Mon Oct 05 15:54:42 2026 +0200"
      },
      "committer": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Mon Oct 05 15:54:42 2026 +0200"
      },
      "message": "feat(allocate): return the allocated CVE ID as JSON to token callers\n\nPOST /allocatecve answered every request with HTML, so a tool using a\nBearer token had to scrape the CVE ID out of a link. Requests with a\nBearer token now get JSON: the allocated IDs on success, 202 when the\nrequest was mailed to the security team instead, and a JSON error with\na matching status otherwise. If saving the record fails, the reserved\nID is still returned. The browser form is unchanged.\n\nGenerated-by: Claude Opus 5\n"
    },
    {
      "commit": "73ec7edd52fcb3eefae10e8fa80f42d2a70593e2",
      "tree": "a2222c1bafd1772f1e1beae4ea9125dc54831e13",
      "parents": [
        "e32434fe67abf41fd0409f3e61a49a9664117b33"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Mon Oct 05 15:54:33 2026 +0200"
      },
      "committer": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Mon Oct 05 15:54:33 2026 +0200"
      },
      "message": "feat(token): allow requesting allocate tokens through the browser\n\nA tool can already allocate a CVE by opening /allocatecve in the\nbrowser, but an allocate token from the browser flow lets it run the\nwhole allocation without the user copying a token by hand.\n\nAlso drop the CORS remark from A6 (it is the Authorization header not\nbeing sent by browsers that matters), drop the shared-store open\nquestion, and say what the end-to-end run did and did not cover.\n\nGenerated-by: Claude Opus 5\n"
    },
    {
      "commit": "e32434fe67abf41fd0409f3e61a49a9664117b33",
      "tree": "6dfdcdbbe5d05c6598ab1e14c039509ea2e97a2e",
      "parents": [
        "61df422e2520c5389a9250e7fafcc74589b02d25",
        "8b0f14707e6d9d907710a9e692e30a4cab98af29"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Tue Sep 29 12:23:03 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 29 12:23:03 2026 +0200"
      },
      "message": "Merge branch \u0027main\u0027 into token-authorize"
    },
    {
      "commit": "8b0f14707e6d9d907710a9e692e30a4cab98af29",
      "tree": "ccc18a773e35b3e2fd8252db5bfbb6c0fadafaeb",
      "parents": [
        "52fc95930cb632ae757ba0da780e04fe73e2fad3"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Sun Sep 27 15:05:11 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Sep 27 15:05:11 2026 +0200"
      },
      "message": "fix: apply PMC record ownership consistently across record routes (#265)\n\n* fix: apply PMC record ownership consistently across record routes\n\nRoute the owner check through two helpers in custom/asf.js,\nasfdocacl() for a single record and asfownerquery() for queries, and\nuse them on the JSON, list, enum/examples, aggregate and bulk-update\nroutes, on saving and creating a record, on comments and on\nattachments. The security team keeps access to every record, and\nsections without PMC-owned records are unaffected.\n\nGenerated-by: Claude Opus 5\n\n* fixup! fix: apply PMC record ownership consistently across record routes\n\nGenerated-by: Claude Opus 5"
    },
    {
      "commit": "61df422e2520c5389a9250e7fafcc74589b02d25",
      "tree": "86eb77bf7f7eef851bee961e27a46e8d2092c3db",
      "parents": [
        "c293f25f9557d4d48cb2948020324b999cc28aed"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Sat Sep 26 14:18:14 2026 +0200"
      },
      "committer": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Sat Sep 26 14:18:14 2026 +0200"
      },
      "message": "docs(token): add a design doc for browser-approved tokens\n\nDescribes the problem, the RFC 8252 + PKCE flow, the assumptions it\nrests on, and numbered invariants mapped to code and tests, so the\ndesign can be reviewed on its own and the implementation checked\nagainst it.\n\nGenerated-by: Claude Opus 5\n"
    },
    {
      "commit": "c293f25f9557d4d48cb2948020324b999cc28aed",
      "tree": "51a4a342a026ae5a0377afc3e90533749f33b081",
      "parents": [
        "52fc95930cb632ae757ba0da780e04fe73e2fad3"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Fri Sep 25 21:22:29 2026 +0200"
      },
      "committer": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Fri Sep 25 21:22:29 2026 +0200"
      },
      "message": "feat(token): let tools request a PMC-scoped token through the browser\n\nA command-line tool can now get an API token without the user copying it\nfrom /users/token. The tool opens /users/token/authorize with a PMC, a\nscope (read or write), a loopback redirect_uri, a state and a PKCE\nchallenge. The user logs in (MFA included), sees what is asked for, and\napproves or denies. On approval the browser is redirected to the tool\nwith a one-time code, which the tool exchanges with its PKCE verifier at\nPOST /users/token/exchange. This is the OAuth 2.0 native-app flow\n(RFC 8252 with RFC 7636 PKCE), so the token never appears in a URL or in\nthe browser history.\n\nPMC tokens are now limited to their PMC: a token acts as its owner with\npmcs narrowed to the token\u0027s PMC, so the record ACLs keep it away from\nthe owner\u0027s other PMCs (and from the security team\u0027s access to all of\nthem). This tightens the existing write and allocate tokens too.\n\nAdds a `read` scope (GET/HEAD on record URLs only), listed on\n/users/token next to allocate and write. /users/token now fills in\nmissing tokens instead of resetting the map, so a token issued through\nthe browser flow survives a later visit to that page.\n\nRefs #246\n\nGenerated-by: Claude Opus 5\n"
    },
    {
      "commit": "52fc95930cb632ae757ba0da780e04fe73e2fad3",
      "tree": "46cba255fa3fe41c95759eded29a47f6eb021dc2",
      "parents": [
        "f29199c2de56cdd67531892f4f144d5bbf14065b"
      ],
      "author": {
        "name": "Shreemaan Abhishek",
        "email": "shreemaan.abhishek@gmail.com",
        "time": "Tue Sep 22 19:04:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 22 13:04:07 2026 +0200"
      },
      "message": "feat: show CVSS ratings in notification emails (#225)\n\n* feat: show CVSS ratings in notification emails\n\nCloses #166\n\n* ci: bump codeql-action/autobuild to v4\n\ninit and analyze are already on v4; the v3 autobuild step rejects the v4 config.\n\n* fix: keep Severity line unconditional, print scores with one decimal\n\nRestores the always-present Severity cue from 6adde6a, formats numeric\nscores as 10.0 rather than 10, and keys the CVSS line on vectorString.\n\n* fix: indent CVSS lines under the severity rating\n\nMakes the CVSS metrics read as details of the severity instead of a flat sibling list."
    },
    {
      "commit": "f29199c2de56cdd67531892f4f144d5bbf14065b",
      "tree": "d76ed344cd185e2d31a5373e3a43af89a2188077",
      "parents": [
        "a9dc776fda0acc31e09694415341c3b499ed602b"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed Sep 16 12:30:37 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 16 12:30:37 2026 +0200"
      },
      "message": "fix(cve5): do not require the Package URL (#258)\n\na9dc776 set a boolean `required: true` on packageURL to keep its editor\nalive across a non-initial setValue, on the assumption that a boolean\nrequired adds no validation rule. json-editor\u0027s validator honours that\ndraft-3 style boolean: when the property is undefined it reports\n\"Property must be set\". The editor also strips empty properties from the\nvalue, so an empty Package URL is undefined at validation time, and every\nrecord without one failed validation.\n\nDrop the boolean. The editor only receives a non-initial setValue after a\nSource tab edit, a collaborator\u0027s realtime patch or a draft restore, and\nonly then does an empty Package URL input disappear until the page is\nreloaded, as it did before a9dc776. product keeps its boolean required,\nsince a missing product name should be reported.\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "a9dc776fda0acc31e09694415341c3b499ed602b",
      "tree": "ca86d8fb1b3d8beacf95efcfe403b96447ed4db8",
      "parents": [
        "ae349ac8154cc4a50e3d9d66fd86fb0e82fce071"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed Sep 16 02:46:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 16 02:46:08 2026 +0200"
      },
      "message": "feat(cve5): derive legacy package identifiers from the Package URL (#253)\n\n* build: vendor packageurl-js for use in the browser\n\nThe CVE 5 editor needs to parse Package URLs client-side. packageurl-js is\npublished as CommonJS only - no ESM or UMD entry, no prebuilt bundle - and is\nnot on cdnjs, so it cannot be loaded from a plain \u003cscript src\u003e tag, which is\nhow every other library here is loaded.\n\nAdd a small CommonJS micro-bundler, in the same spirit as bundle-editor.js,\nthat wraps the package into one classic script exposing a PackageURL global,\nand commit the generated file alongside the other vendored libraries.\n\nThe standalone build copies that bundle rather than minifying it: packageurl-js\nuses optional catch binding, ?. and ??, none of which uglify-es 3.3.10 can\nparse.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* feat(cve5): derive legacy package identifiers from the Package URL\n\nAn affected product entry is identified either by vendor + product or by\ncollectionURL + packageName; a packageURL alone does not satisfy the \u0027pE\u0027\nvalidator. Someone entering pkg:maven/org.apache.commons/commons-lang3 still\nhad to look up which of the 62 collection URLs is Maven\u0027s and retype the same\npackage identity by hand.\n\nWhile the Package URL maps to a known package collection, collectionURL and\npackageName are now derived from it and disabled, so the two cannot drift\napart. They are handed back when the purl is cleared, or names a type with no\nmeaningful collection URL such as pkg:generic. The fields update as soon as\nwhat is typed becomes a usable purl, without leaving the field.\n\nValues are only ever rewritten from a real user edit, so opening a record -\nor receiving it over realtime, or restoring a draft - never rewrites what it\nstores. A stored record whose legacy fields disagree with its purl keeps them\nand is reported by the validator instead.\n\nCovers the officially registered purl types, with collection URLs taken from\nthe CVE 5 schema\u0027s own examples where it has one. Parsing is delegated to\npackageurl-js, so percent-decoding, per-type normalisation and per-type\nvalidation follow the spec.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* chore: add a database-free preview for the editor UI\n\nWorking on the editor front end otherwise needs MongoDB, a login and the CVE\nServices API. This serves the real editor page with the document, the user and\nthe realtime socket stubbed out, so schema, preload.js and script.js changes\ncan be checked by reloading a page.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* feat(cve5): reject a version in the Package URL\n\nThe CVE 5 schema states the Package URL MUST NOT include a version - the\naffected versions belong in `versions` - but nothing said so. A purl carrying\none was quietly accepted, and the version silently ignored when deriving the\nlegacy identifiers.\n\nReport it on the packageURL field instead. The identifiers are still derived\nfrom a versioned purl, so this does not also produce a spurious mismatch, and\nqualifiers and a subpath remain legitimate.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* feat(cve5): derive the legacy identifiers on publication, not in the record\n\nReview feedback: hide collectionURL and packageName from the editor the way\nCPEs are hidden - the block appears only if the JSON already contains it - while\nstill deriving the values and showing them, and treating records submitted\nthrough the API the same as records authored in the editor.\n\nHiding them and writing them are mutually exclusive: anything written into the\ndocument is \"present in the JSON\" and reappears on the next load. So packageURL\nbecomes the only stored source of truth and textUtil.reduceJSON derives the pair\nwhen the record is serialised. Both the CVE-JSON tab and customRoutes/publishcve.js\ngo through reduceJSON, so every route to cve.org gets the same result no matter\nhow the record was created, while what is stored stays as authored.\n\nThe desync this replaces is now structurally impossible rather than managed, so\nthe field locking, the purlLocked flag and the always_disabled workaround are all\ngone. In their place the Package URL field carries a read-only line naming what\nit resolves to, suppressed when the record already carries the identifiers -\nmirroring reduceJSON, which only fills the pair when both are absent.\n\nreduceJSON fills only what is absent. A record whose legacy fields disagree with\nits purl keeps them and is reported by the validator, which now names the value\nthe purl implies; publishing must not rewrite authored data.\n\nPer review, the ASF-specific parts live under custom/cve5 rather than default:\nthe derivation table in a new script.js (inlined into opts.script for the page,\nrequire()-d by publishcve.js for the server), the editor in asfpreload.js, the\nvalidators and the schema option in conf.js, the packageurl-js tag in edit.pug.\nTwo things cannot move. The reduceJSON call site is in the shared, bundled\nsrc/js/edit/util.js, reduced to a guarded call to a global exactly as the ASF\nblock there already does for getProductListNoVendor. And defaultProperties\ncannot be shortened from the overlay, because extend() merges arrays by index,\nso that one deletion stays in default/cve5/cve5.schema.json.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* fix(cve5): put the Package URL beside the product name\n\nThe purl field was 12 grid columns wide, so it could not share the row with the\nproduct name and wrapped, leaving the eight columns where collectionURL and\npackageName used to sit empty. 4 + 8 fills the row.\n\nLabel the derived values in the hint the way the fields themselves are labelled,\nand let it wrap rather than run past the narrower column.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* feat(cve5): explain the derived identifiers on the Package URL field\n\nWith the legacy fields hidden, nothing on screen said where the values under the\nPackage URL come from or when they appear. Add the infoText tooltip the\nneighbouring product fields already carry.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* Fix test code to satisfy CodeQL\n\nCo-authored-by: Copilot Autofix powered by AI \u003c62310815+github-advanced-security[bot]@users.noreply.github.com\u003e\n\n* fix(test): compare the mismatch message instead of parsing a URL out of it\n\nThe CodeQL autofix pulled the URL back out of the message with\n/https?:\\/\\/[^\\s)]+/, but the URL is quoted there, so the trailing quote was\ncaptured too and new URL() percent-encoded it into the path - the pathname\nassertion compared \u0027/maven2%22\u0027 against \u0027/maven2\u0027 and failed.\n\nCompare the whole message instead. That still avoids the substring check the\nrule objects to, asserts more than the original did, and derives the expected\nURL from the fixture so it cannot drift.\n\nAssisted-By: Claude Opus 5 (1M context) \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01RQEe8VKNpiBQ12ZwUHFLZn\n\n* fix(cve5): hide the legacy identifiers from the ASF overlay, not the schema\n\nReview feedback: keep default/cve5/cve5.schema.json identical to upstream and\nhide collectionURL and packageName with the \"hidden\" option in\ncustom/cve5/conf.js, like the other ASF-hidden product fields, so future\nupstream merges of the schema do not conflict.\n\nA hidden editor is still built and still holds whatever the record carries, so\nthe Package URL hint and the mismatch validator keep working as before.\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n* feat(cve5): show the legacy identifiers when the record carries them\n\nThe legacy identifiers are hidden while empty - a new record derives them from\nthe Package URL on publication - but a record that already carries them must\nkeep them visible and editable. Introduce a hideWhenEmpty editor in\nasfpreload.js that toggles its own options.hidden from its value and asks the\nproduct entry to lay its grid out again; conf.js selects it for collectionURL\nand packageName instead of the static \"hidden\" option, keeping the schema\nuntouched.\n\nThe relayout exposed two json-editor quirks the editor works around: the\nlayout sets display none on a hidden editor but never clears it, and the\ntheme appends a \"col sN\" class on every layout without removing the previous\none, so the widest CSS rule won after a show/hide cycle.\n\nVerified headlessly against scripts/preview-editor.js: an empty record hides\nboth fields, a record carrying them shows them, clearing one hides it again\nand the Package URL hint takes over once both are empty.\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n* fix: remove mention of cdnjs\n\nCo-authored-by: Arnout Engelen \u003cengelen@apache.org\u003e\n\n* fix(preview): contain served files with a relative-path check, not a prefix\n\nReview feedback: \"startsWith(root)\" also accepts a sibling directory whose\nname shares the prefix, e.g. \"../static-other\" under \".../static\", and the\nstatic branch did not check that the target is a regular file. Both branches\nnow go through fileUnder(), which resolves the path, rejects anything that\npath.relative places outside the root, and requires isFile().\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n* fix(cve5): look the purl tables up by own key, and map the gitlab type\n\nReview feedback. A purl type may legitimately be \"constructor\" and a\nnamespace may be anything, \"__proto__\" included, so a plain property lookup\non the rule tables found Object.prototype members: pkg:constructor/foo/bar\nthrew and pkg:deb/__proto__/curl returned an object as the collection URL.\nBoth lookups now use an own-key helper and the collection URL must be a\nstring.\n\nAlso add the gitlab type, whose collection URL the CVE schema lists next to\nGitHub\u0027s.\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n* fix(cve5): show the legacy identifiers as a pair\n\nReview feedback: with each field hidden on its own, a record carrying only\ncollectionURL left packageName hidden while the Maven validator reported it\nmissing, an error on a control the user could not see. The hideWhenEmpty\noption now names a group, and every editor in the group is shown while any\nmember has a value.\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n* fix(preview): never serve TLS, whatever the shell says\n\nReview feedback: the override only applied when VULNOGRAM_TLS_ENABLED was\nunset, so a shell that had it set to true made config/conf.js read the\nproduction certificate paths and the preview failed before starting.\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n* fix(cve5): keep the product name and Package URL editors after a reset\n\njson-editor drops the editor of any optional property that is missing from a\ndocument set after the initial load, and remove_empty_properties makes an\nempty string missing. Realtime updates and draft restores set such documents,\nso saving a record with no product name made the Product Name field vanish,\nand the Package URL with it. CVE 5.1 lists neither as required.\n\nA boolean \"required\" on the property schema is honoured by json-editor\u0027s\nisRequiredObject and isRequired but ignored by the validator, so the two\neditors now stay and carry the required star without a new validation rule.\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n* style(cve5): one clause per comment line in the product overlay\n\nAssisted-By: Claude Fable 5.1 \u003cnoreply@anthropic.com\u003e\n\n---------\n\nCo-authored-by: Copilot Autofix powered by AI \u003c62310815+github-advanced-security[bot]@users.noreply.github.com\u003e\nCo-authored-by: Arnout Engelen \u003cengelen@apache.org\u003e"
    },
    {
      "commit": "ae349ac8154cc4a50e3d9d66fd86fb0e82fce071",
      "tree": "2827ff78b72caca30b4344899c5332d0dace324f",
      "parents": [
        "3212b85a2e49a1e11d87cba1a99b93e2113e0a8a"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Tue Sep 15 23:16:52 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 15 23:16:52 2026 +0200"
      },
      "message": "fix: default metrics for new advisories (#256)"
    },
    {
      "commit": "3212b85a2e49a1e11d87cba1a99b93e2113e0a8a",
      "tree": "7cdee824bd2fff22ad451fa33469ca9d41f0da42",
      "parents": [
        "ec4b71d2daa9755e47b29b3f9d58f4dbeb74825c"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Tue Sep 15 23:16:04 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 15 23:16:04 2026 +0200"
      },
      "message": "auth: make more oauth parameters configurable (#251)\n\nto unlock testing via https://mfa-dev.apache.org/"
    },
    {
      "commit": "ec4b71d2daa9755e47b29b3f9d58f4dbeb74825c",
      "tree": "1b5345198ddc863c6ec136dcca1fcd74e52b4901",
      "parents": [
        "4ea483599b0e9864ea888cd91ae84a410cf35457",
        "22f36c73ddb7a81d3d78dcaa98da7439feddf758"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Thu Sep 10 17:48:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 10 17:48:59 2026 +0200"
      },
      "message": "Merge pull request #252 from raboof/api-allocate\n\nfeat(allocate): allow allocating CVEs using a Bearer token"
    },
    {
      "commit": "22f36c73ddb7a81d3d78dcaa98da7439feddf758",
      "tree": "1b5345198ddc863c6ec136dcca1fcd74e52b4901",
      "parents": [
        "4ea483599b0e9864ea888cd91ae84a410cf35457"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Sep 09 13:54:50 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Sep 09 13:56:07 2026 +0200"
      },
      "message": "feat(allocate): allow allocating CVEs using a Bearer token\n"
    },
    {
      "commit": "4ea483599b0e9864ea888cd91ae84a410cf35457",
      "tree": "b9ec3f7a9395b28164689b6b26a0d4972923b08d",
      "parents": [
        "dacfb6117ce3bdee5bb86d183b40af24066f9131"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Tue Sep 08 20:46:35 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 08 20:46:35 2026 +0200"
      },
      "message": "require at least one severity rating (#250)\n\nfixes #222\n\n(doesn\u0027t change validation, but removes the possibility of\nremoving the last metric)"
    },
    {
      "commit": "dacfb6117ce3bdee5bb86d183b40af24066f9131",
      "tree": "4f3d8df5db20f39b7070385695d6d05d118b9dd7",
      "parents": [
        "429016492364ea4cbeccc8bac48cde54028c22ff"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Sun Sep 06 10:26:55 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Sun Sep 06 10:26:55 2026 +0200"
      },
      "message": "deployment: don\u0027t restart update-deps jobs\n"
    },
    {
      "commit": "429016492364ea4cbeccc8bac48cde54028c22ff",
      "tree": "36d5f37b95ad5822055e9ee317c025c1f83a9410",
      "parents": [
        "91a58600113f36cf70f1d44bee98432388e77cf0"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Sep 04 10:24:52 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 04 10:24:52 2026 +0200"
      },
      "message": "fix(cvepublish): show error when CVE publication fails (#247)\n\nFixes #243"
    },
    {
      "commit": "91a58600113f36cf70f1d44bee98432388e77cf0",
      "tree": "1713567473105fb5a5485b1350cb1d6f11016dfe",
      "parents": [
        "1b5a7fb4453316b4399cb322f67cfa4ebd2db7c7"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Sep 04 10:24:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 04 10:24:08 2026 +0200"
      },
      "message": "feat: don\u0027t redirect after publishing (#238)\n\nunclear what that\u0027s good for\n\nfixes #232"
    },
    {
      "commit": "1b5a7fb4453316b4399cb322f67cfa4ebd2db7c7",
      "tree": "2cf3ae37823903967165da77b4afdd86e7160dc8",
      "parents": [
        "b6062716c110b2ec38bf91a76838539eaa776b23",
        "7c506197060ee3897f5d00aeb1bf1744b10c0793"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Tue Sep 01 08:54:03 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 01 08:54:03 2026 +0200"
      },
      "message": "Merge pull request #244 from apache/fix/asf-metric-missing-type\n\nfix: ASF severity metric added to existing record lacks \u0027other.type\u0027"
    },
    {
      "commit": "7c506197060ee3897f5d00aeb1bf1744b10c0793",
      "tree": "2cf3ae37823903967165da77b4afdd86e7160dc8",
      "parents": [
        "04df207ca2bcb70c19fd7818be0534f87c65df4a"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Aug 31 20:41:09 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Aug 31 20:41:09 2026 +0200"
      },
      "message": "fix: minimize change\n"
    },
    {
      "commit": "04df207ca2bcb70c19fd7818be0534f87c65df4a",
      "tree": "c7efcc3726aaf19b36b043a4cf98b0d0d7f4dcde",
      "parents": [
        "b6062716c110b2ec38bf91a76838539eaa776b23"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Aug 31 16:46:04 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Mon Aug 31 16:46:04 2026 +0200"
      },
      "message": "fix: ASF severity metric added to existing record lacks \u0027other.type\u0027\n\nThe required \"type\": \"Textual description of severity\" was only set via\nthe array-level default on \u0027metrics\u0027, which json-editor applies solely\nwhen instantiating the array from scratch. A metric row added after a\nCVSS entry (or any metric on a reopened draft, since\ncveFixForVulnogram seeds \u0027cna.metrics \u003d []\u0027) was instead seeded\nproperty-by-property: \u0027other.type\u0027 had no default, became \"\" and was\nthen stripped by the global \u0027remove_empty_properties\u0027, producing a\nrecord that CVE Services rejects while local validation stayed silent.\n\nFix in three layers:\n- add a per-property default for \u0027other.type\u0027 and a default on the\n  \"ASF severity rating\" oneOf branch (which previously inherited\n  upstream\u0027s wrong \u0027{type: \"text\"}\u0027), so every editor seeding path\n  yields the correct value;\n- backfill a missing/empty \u0027other.type\u0027 in cveFixForVulnogram so\n  already-damaged records are repaired on load (non-empty foreign\n  type strings are preserved);\n- extend the ASF metrics validator to flag a missing \u0027type\u0027 before\n  submission as a safety net.\n\nVerified with a headless-browser harness driving the real\njsoneditor.min.js/vg-editor.js against the merged schema: the pre-fix\nschema reproduces the bug (\u0027{\"other\": {}}\u0027), the fixed one yields the\ncorrect type for rows added after CVSS and on empty arrays, and the\nbackfill/round-trip scenarios pass.\n\nAssisted-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e\nClaude-Session: https://claude.ai/code/session_01SjEqCjZbEzcmRFzzm4wHjc\n"
    },
    {
      "commit": "b6062716c110b2ec38bf91a76838539eaa776b23",
      "tree": "ba8891dceacfae397f55ae3ba6ecbfd38c4057c6",
      "parents": [
        "99eab23fd0e88af1c138770babb1a540da619ef0"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 31 14:29:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:29:08 2026 +0200"
      },
      "message": "feat: accept pmc, title and message/list id (#241)\n\nfixes #214"
    },
    {
      "commit": "99eab23fd0e88af1c138770babb1a540da619ef0",
      "tree": "a5a99750b3b77c3d9e7114e8e8c2ac047c3ffcf0",
      "parents": [
        "bab161ae899e6195e45ca1a718e99b838db55449"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 31 14:23:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:23:08 2026 +0200"
      },
      "message": "feat: hide sidebar (#239)\n\nfixes #234"
    },
    {
      "commit": "bab161ae899e6195e45ca1a718e99b838db55449",
      "tree": "19cadb53d99f1eb3c3396c109aa5ce0d5df9b992",
      "parents": [
        "4cf0318109b222eca9e46b07dcbdcf0ce05044b7"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 31 14:18:52 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:18:52 2026 +0200"
      },
      "message": "chore: hide \u0027Scoring scenarios\u0027 from metrics (#237)\n\nIt\u0027s rarely used and just distracts, especially for the ASF text\nseverity rating, but honestly also when using CVSS.\n\nFixes #217"
    },
    {
      "commit": "4cf0318109b222eca9e46b07dcbdcf0ce05044b7",
      "tree": "da41bf70f4876566c90cd8df9e421068f5307028",
      "parents": [
        "f097fa27cb707ea13f2e177458bcd4a9d650b6fb"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 31 14:17:25 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:17:25 2026 +0200"
      },
      "message": "fix: comment footer link (#235)\n\n`req.client.servername` is only populated by the\nTLS handshake and we don\u0027t do that in vulnogram\nanymore. In theory `host` could be spoofed but\nit\u0027s hard to imagine a scenario where that would\nbe a problem.\n\nFixes #221"
    },
    {
      "commit": "f097fa27cb707ea13f2e177458bcd4a9d650b6fb",
      "tree": "d608bf091db69ccfb26da9137bf145ec0a8a3e20",
      "parents": [
        "de8449b19a5af511ea9410090e1b5df63580d190"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 31 14:17:04 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:17:04 2026 +0200"
      },
      "message": "fix(api): allow POST via API (#228)\n\nMoves the CSRF protection to app.js so that API users\ncan use Bearer token authorization without providing a CSRF\ntoken as well."
    },
    {
      "commit": "de8449b19a5af511ea9410090e1b5df63580d190",
      "tree": "8f9bbe00460360a698f3ab9b33e903dabbb60353",
      "parents": [
        "b1f8793d478e282316d94a81c5ca712cdef06d8b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Aug 31 14:10:20 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:10:20 2026 +0200"
      },
      "message": "Bump actions/setup-node from 6 to 7 (#230)\n\nBumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-node\n  dependency-version: \u00277\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "b1f8793d478e282316d94a81c5ca712cdef06d8b",
      "tree": "1fafb1153f4ba35a96ef98e5fcd8b27cf51cc176",
      "parents": [
        "eb3de5eb21a4a96b5e7e9c6f0b5b9a2372c628ac",
        "507f539ce4f08db72794a53f23dcf7021877aeab"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Aug 28 15:09:49 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 28 15:09:49 2026 +0200"
      },
      "message": "Merge pull request #231 from apache/dependabot/github_actions/actions/checkout-7\n\nBump actions/checkout from 6 to 7"
    },
    {
      "commit": "507f539ce4f08db72794a53f23dcf7021877aeab",
      "tree": "1fafb1153f4ba35a96ef98e5fcd8b27cf51cc176",
      "parents": [
        "eb3de5eb21a4a96b5e7e9c6f0b5b9a2372c628ac"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Aug 28 13:02:02 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 28 13:02:02 2026 +0000"
      },
      "message": "Bump actions/checkout from 6 to 7\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: \u00277\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "eb3de5eb21a4a96b5e7e9c6f0b5b9a2372c628ac",
      "tree": "7214f224f099d80009fbe68706d1dc007b50875e",
      "parents": [
        "e2615dbf239f5e8e14f3c3f53a52778c3a38168b",
        "b73f1b40dd304df1c55d7c513bcf3aa6111e3d8b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Aug 28 15:00:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 28 15:00:27 2026 +0200"
      },
      "message": "Merge pull request #236 from raboof/fix-codeql\n\nchore(ci): fix codeql"
    },
    {
      "commit": "b73f1b40dd304df1c55d7c513bcf3aa6111e3d8b",
      "tree": "7214f224f099d80009fbe68706d1dc007b50875e",
      "parents": [
        "e2615dbf239f5e8e14f3c3f53a52778c3a38168b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Aug 27 13:49:45 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Aug 27 13:53:47 2026 +0200"
      },
      "message": "chore(ci): fix codeql\n\nmake it more consistent with upstream again by specifying the language\nexplicitly, and make sure the action versions are consistent\n"
    },
    {
      "commit": "e2615dbf239f5e8e14f3c3f53a52778c3a38168b",
      "tree": "1992cec86ae349b607095cdd0c3617dbe679ef91",
      "parents": [
        "eeaf8fa90df806edd41af1cdb3cdd485e09685ab",
        "280cb9aa983d425a222a83aa25c092331f1eddd0"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Wed Aug 26 16:46:10 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 26 16:46:10 2026 +0200"
      },
      "message": "Merge pull request #227 from raboof/fix-sending-notification-emails\n\nfix: sending notification emails"
    },
    {
      "commit": "eeaf8fa90df806edd41af1cdb3cdd485e09685ab",
      "tree": "27c8497bb4c2f3c7a153d3d321e020a1bca75e0e",
      "parents": [
        "d13b7ccab8638cc0995d9b09ca8918bd92e45162",
        "a710c6c588c25c12c59d28cf425ac93157167d29"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Wed Aug 26 12:47:35 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 26 12:47:35 2026 +0200"
      },
      "message": "Merge pull request #229 from raboof/remove-cveportal-from-sidebar\n\nremove CVE portal from sidebar"
    },
    {
      "commit": "d13b7ccab8638cc0995d9b09ca8918bd92e45162",
      "tree": "f047a621e9811e7f6f8a294fd4c4474853442b5a",
      "parents": [
        "790d6c9f415d215fc8055285463cb4beffaf054d",
        "9c9b6c3f547d2886494e363ae13ed56055cd2ddd"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Wed Aug 26 12:47:18 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 26 12:47:18 2026 +0200"
      },
      "message": "Merge pull request #205 from apache/pmcs-with-security-emails\n\nconf: superset has a security list"
    },
    {
      "commit": "9c9b6c3f547d2886494e363ae13ed56055cd2ddd",
      "tree": "a5afd38f2f66014bc81f0ae219eda8b52edbc039",
      "parents": [
        "a0bb7209d93f5b17a5f7039b76544698a516979f"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Wed Aug 26 11:55:07 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 26 11:55:07 2026 +0200"
      },
      "message": "add more missing security lists\n\nCo-authored-by: Piotr P. Karwasz \u003cpkarwasz-github@apache.org\u003e"
    },
    {
      "commit": "280cb9aa983d425a222a83aa25c092331f1eddd0",
      "tree": "5187b680c2e354cb4aaed4a78dcafbcb45e1fcbf",
      "parents": [
        "790d6c9f415d215fc8055285463cb4beffaf054d"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Aug 26 10:07:21 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Wed Aug 26 10:07:21 2026 +0200"
      },
      "message": "fix: sending notification emails\n\napparently we must no longer `res.end()` explicitly when we\n`res.render()`, because then we get\n`Error [ERR_HTTP_HEADERS_SENT]: Cannot set headers after they are sent\nto the client`\n"
    },
    {
      "commit": "790d6c9f415d215fc8055285463cb4beffaf054d",
      "tree": "01b40da642df8f9ae537e048f2acd7595642c2af",
      "parents": [
        "8c89f368b8a3a7327a591080ecac530d6d815175",
        "687a750fe14aa9846dc18c2c5fff5c6cc81d11d2"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 24 12:42:06 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 12:42:06 2026 +0200"
      },
      "message": "Merge pull request #220 from raboof/fix\n\nfix: merge mistake"
    },
    {
      "commit": "687a750fe14aa9846dc18c2c5fff5c6cc81d11d2",
      "tree": "01b40da642df8f9ae537e048f2acd7595642c2af",
      "parents": [
        "8c89f368b8a3a7327a591080ecac530d6d815175"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Aug 24 12:24:33 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Aug 24 12:39:43 2026 +0200"
      },
      "message": "fix: follow-up on publicjson fixes\n\nmade a mistake merging, used wrong cve4 collection\n"
    },
    {
      "commit": "8c89f368b8a3a7327a591080ecac530d6d815175",
      "tree": "8e7dfec264b8f7edc8d38132afd65c68e599ea06",
      "parents": [
        "df41369d05088d8cd6e6b74d67b09a4917b6f826",
        "7a72dde7371e75dafe48bf3bb6f35a36a906aa7a"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 24 12:21:46 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 12:21:46 2026 +0200"
      },
      "message": "Merge pull request #219 from raboof/use-promise-mongo-api\n\nfix(api): fetch public CVEs"
    },
    {
      "commit": "7a72dde7371e75dafe48bf3bb6f35a36a906aa7a",
      "tree": "8e7dfec264b8f7edc8d38132afd65c68e599ea06",
      "parents": [
        "df41369d05088d8cd6e6b74d67b09a4917b6f826"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Aug 24 11:22:09 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Aug 24 11:22:09 2026 +0200"
      },
      "message": "fix(api): fetch public CVEs\n\nSwitch to the promise-based API and allow fetching CVE4-era CVEs\neven though we don\u0027t expose those in the UI anymore.\n"
    },
    {
      "commit": "df41369d05088d8cd6e6b74d67b09a4917b6f826",
      "tree": "5cb1b17dfa901c5ae4079f6e7b18a35266a77fff",
      "parents": [
        "263e44df11a29fef70fb66c2dafeacdfef90ba14",
        "fad0f3528bd3fec929f725745e5ad75044dbd831"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon Aug 24 10:49:53 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 10:49:53 2026 +0200"
      },
      "message": "Merge pull request #218 from apache/main-next\n\nUpdate main branch"
    },
    {
      "commit": "fad0f3528bd3fec929f725745e5ad75044dbd831",
      "tree": "81a273f1ae07c7916b517babfe1b178d7d98e0d0",
      "parents": [
        "23b08e04ff93dc8c277171e92e76f8cfe7c142e8"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Wed Aug 12 16:34:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 12 16:34:29 2026 +0200"
      },
      "message": "fix: use correct header name for bearer tokens (#212)"
    },
    {
      "commit": "23b08e04ff93dc8c277171e92e76f8cfe7c142e8",
      "tree": "acd69a2486bc7568da5e88fbe368e37bda91926e",
      "parents": [
        "ea23c5c5251dc100958be4bd0980927e3782bac3"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Thu Jul 23 19:20:51 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 23 19:20:51 2026 +0200"
      },
      "message": "feat: poor man\u0027s token auth (#211)\n\nTo allow populating CVE\u0027s via automation. Still missing features\nlike expiration, explicit rotation, audit logs - but perhaps those\nshould come when we introduce a cross-service facility for this?"
    },
    {
      "commit": "ea23c5c5251dc100958be4bd0980927e3782bac3",
      "tree": "953bddef1233855624514e47353959f323db1caf",
      "parents": [
        "5d8f62cc8601f66b0d1b703c47f4e80260176e7c"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jul 06 17:42:36 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jul 06 17:42:36 2026 +0200"
      },
      "message": "mount postfix drop dir\n"
    },
    {
      "commit": "5d8f62cc8601f66b0d1b703c47f4e80260176e7c",
      "tree": "959b6be449f9cac701ac253411e8c7040df7f8e8",
      "parents": [
        "d68fb40190dcea0046ef00b29bf3d88c8327bc4e"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 29 09:22:34 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 29 09:22:34 2026 +0200"
      },
      "message": "test instance of vulnogram\n"
    },
    {
      "commit": "263e44df11a29fef70fb66c2dafeacdfef90ba14",
      "tree": "bb83191de7c32681b1b9e8ecca57af6231494beb",
      "parents": [
        "189396b083360f5f39ca86555d14442833b6c910"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jun 24 12:59:21 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 24 12:59:21 2026 +0200"
      },
      "message": "Bump github/codeql-action from 3 to 4 (#206)\n\nBumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/v3...v4)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action\n  dependency-version: \u00274\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "189396b083360f5f39ca86555d14442833b6c910",
      "tree": "a5eeaf2fdd8db514efd64e21af7f7c6dbf698101",
      "parents": [
        "61b243770bf7f2f030c28eb5f6f9d443c6e2d85b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jun 24 11:49:32 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 24 11:49:32 2026 +0200"
      },
      "message": "Bump actions/checkout from 6 to 7 (#208)\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: \u00277\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d68fb40190dcea0046ef00b29bf3d88c8327bc4e",
      "tree": "c0e5b74d954e2ccf82f24c1849f9db5979678ce2",
      "parents": [
        "633a77d3537af2213bb0f92a22cf2be79a63a606"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Jun 19 10:10:40 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 19 10:10:40 2026 +0200"
      },
      "message": "deployment: support deploying new version as pipservice (#207)\n\n* initial pipservice definition\n\n* npm install in the sandbox\n\n* temporary homedir to make npm happier\n\n* protecthome is no longer needed since we use a tmpfs\n\n* pipservice: separate one to install deps in the sandbox\n\n* option to disable TLS\n\nAs TLS will be offloaded to Apache on prod\n\n* pipservice: for running, also mount program dir readonly\n\n* deployment: trust local proxy"
    },
    {
      "commit": "633a77d3537af2213bb0f92a22cf2be79a63a606",
      "tree": "f2716556f81ee5ca23c87654e203ea5e20a1ac93",
      "parents": [
        "11aab0dd769d4ce5af2873ac77b91c9032e2f16d",
        "77cee12e234e9c84de2e08e252a91fd0f55f4845"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 19 10:09:31 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 19 10:09:31 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027origin/main-next\u0027 into main-next\n"
    },
    {
      "commit": "11aab0dd769d4ce5af2873ac77b91c9032e2f16d",
      "tree": "43514cb9ce72ba15296eafc789a9db3cea4d971b",
      "parents": [
        "cad79969f9dfcb6b23e7d3daafbbcfadac460fc4",
        "61b243770bf7f2f030c28eb5f6f9d443c6e2d85b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 19 09:48:46 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri Jun 19 09:48:46 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027origin/main\u0027 into main-next\n"
    },
    {
      "commit": "a0bb7209d93f5b17a5f7039b76544698a516979f",
      "tree": "4da99a88c6b203ad73ae88f19537d0639a15dec7",
      "parents": [
        "61b243770bf7f2f030c28eb5f6f9d443c6e2d85b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 15 09:58:52 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 15 09:58:52 2026 +0200"
      },
      "message": "conf: superset has a security list\n"
    },
    {
      "commit": "61b243770bf7f2f030c28eb5f6f9d443c6e2d85b",
      "tree": "b32e4ab941915ea7c47fd55848ccb704409c617b",
      "parents": [
        "2d33f36bc01e7aea783f5f179b35ea92f75b30d0",
        "e3c83a1bf33e799a01560f04efd25f2a4238f4a3"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri Jun 12 10:01:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 12 10:01:38 2026 +0200"
      },
      "message": "Merge pull request #198 from apache/infrastructure-ruleset-bot/default-branch-protection\n\n[INFRA] Set up default rulesets for default and release branches"
    },
    {
      "commit": "2d33f36bc01e7aea783f5f179b35ea92f75b30d0",
      "tree": "b7df7820875331d0561bedf9c6657240a05e4e69",
      "parents": [
        "12e7ca5afc556494197bbde78ea57d07087a1d8e"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 08 16:13:37 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon Jun 08 16:13:37 2026 +0200"
      },
      "message": "improve logout flow\n\nuse callback as is now needed per\nhttps://medium.com/passportjs/fixing-session-fixation-b2b68619c51d\nand redirect to mfa.apache.org to log out there as well.\n"
    },
    {
      "commit": "12e7ca5afc556494197bbde78ea57d07087a1d8e",
      "tree": "97e595d0dfea42c530ff944996f19013b4d0b776",
      "parents": [
        "cbe31d4360d465e513a0b70b7ca6ec2bbd3228d5"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 25 09:38:25 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 25 09:38:25 2026 +0200"
      },
      "message": "orc and spark have retired their security lists\n"
    },
    {
      "commit": "e3c83a1bf33e799a01560f04efd25f2a4238f4a3",
      "tree": "bbaa858c67ce54a11e605df65342b5cbce6034f2",
      "parents": [
        "cbe31d4360d465e513a0b70b7ca6ec2bbd3228d5"
      ],
      "author": {
        "name": "The Apache Software Foundation",
        "email": "root-asf-gitbox-commits@apache.org",
        "time": "Fri May 15 17:52:04 2026 -0500"
      },
      "committer": {
        "name": "The Apache Software Foundation",
        "email": "root-asf-gitbox-commits@apache.org",
        "time": "Fri May 15 17:52:04 2026 -0500"
      },
      "message": "Set up default protection ruleset for default and release branches"
    },
    {
      "commit": "77cee12e234e9c84de2e08e252a91fd0f55f4845",
      "tree": "30226b76233924833293f8122b2358513c7c15d0",
      "parents": [
        "cad79969f9dfcb6b23e7d3daafbbcfadac460fc4",
        "2660f1e2a251017f955aaaa95e9b60edd13cc554"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Thu May 14 12:20:58 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 14 12:20:58 2026 +0200"
      },
      "message": "Merge pull request #183 from raboof/unittests\n\nfix and run unit tests"
    },
    {
      "commit": "cbe31d4360d465e513a0b70b7ca6ec2bbd3228d5",
      "tree": "d6d48e7db7c3c7ae21df7b0a836fa29d7b22e12c",
      "parents": [
        "567651b232440bcbfb6b9bbec7f3540a37bf151a",
        "a5f37b49b75ef2a9aff7d013cdb5457132a36376"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Mon May 11 17:05:05 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 17:05:05 2026 +0200"
      },
      "message": "Merge pull request #196 from raboof/update-oauth\n\nExpand OAuth implementation"
    },
    {
      "commit": "a5f37b49b75ef2a9aff7d013cdb5457132a36376",
      "tree": "d6d48e7db7c3c7ae21df7b0a836fa29d7b22e12c",
      "parents": [
        "567651b232440bcbfb6b9bbec7f3540a37bf151a"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 11 15:10:11 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 11 15:51:24 2026 +0200"
      },
      "message": "Expand OAuth implementation\n\nSo it works with the new MFA setup\n"
    },
    {
      "commit": "a710c6c588c25c12c59d28cf425ac93157167d29",
      "tree": "8595a3013acbc2bbca0e7f7367e8769e684c90c0",
      "parents": [
        "cad79969f9dfcb6b23e7d3daafbbcfadac460fc4"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 11 15:12:03 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 11 15:12:03 2026 +0200"
      },
      "message": "remove CVE portal from sidebar\n\nForgot to add to commit in #176\n"
    },
    {
      "commit": "2660f1e2a251017f955aaaa95e9b60edd13cc554",
      "tree": "30226b76233924833293f8122b2358513c7c15d0",
      "parents": [
        "cad79969f9dfcb6b23e7d3daafbbcfadac460fc4"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 05 13:14:36 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Fri May 08 09:46:32 2026 +0200"
      },
      "message": "fix and run unit tests\n"
    },
    {
      "commit": "cad79969f9dfcb6b23e7d3daafbbcfadac460fc4",
      "tree": "1cec3d905e5316b6d76f1188fccb6af495b20c33",
      "parents": [
        "567651b232440bcbfb6b9bbec7f3540a37bf151a",
        "8ce80a36a0a942928174f99f8034168c3e6d5a84"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Fri May 08 09:29:57 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 08 09:29:57 2026 +0200"
      },
      "message": "Merge pull request #176 from raboof/integrate-upstream-changes\n\nIntegrate upstream changes"
    },
    {
      "commit": "8ce80a36a0a942928174f99f8034168c3e6d5a84",
      "tree": "1cec3d905e5316b6d76f1188fccb6af495b20c33",
      "parents": [
        "4f1aca49cb51e04d88a2443067121698092d2e04",
        "567651b232440bcbfb6b9bbec7f3540a37bf151a"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Thu May 07 21:53:38 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Thu May 07 21:53:38 2026 +0200"
      },
      "message": "Merge branch \u0027main\u0027 into integrate-upstream-changes\n"
    },
    {
      "commit": "567651b232440bcbfb6b9bbec7f3540a37bf151a",
      "tree": "47905a28836ceead84f535bffb9fb842849fd7fb",
      "parents": [
        "184ccb9964add092b7d553f291ecda0bece30831"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Thu May 07 21:33:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 07 21:33:29 2026 +0200"
      },
      "message": "feat: improve testability of Vulnogram (#194)\n\n* feat: improve testability of Vulnogram\n\nThis change improves the testability of Vulnogram, by:\n\n### `.env` changes\n\nThe usage of `.env` files was inconsistent:\n\n- Docker Compose didn\u0027t use `example.env` for YAML interpolation; it was only loaded inside containers, so the containers could end up listening on different ports than those published on the host.\n\nThis PR adds a new `example-asf.env` file and instructs users to copy it to `.env` before testing.\n\nAlso, `.env` was previously loaded late in startup, after `custom/asf.js` had already used the configuration. This change moves `dotenv.config()` to the top of `app.js`.\n\n### `conf.js` refactoring\n\nThis forked repository committed a `conf.js` with hardcoded ASF production parameters, while upstream keeps `conf.js` in `.gitignore`.\n\nThis change:\n\n- Renames the file to `conf-asf.js` to prevent conflicts.\n- Allows users to override production defaults via the `.env` file.\n\nUsers are instructed to symlink `config/conf.js` to `config/conf-asf.js`.\n\n### Defanging of HTTP requests\n\n`oauth.apache.org` does not accept HTTP callbacks, so the test environment must use a self-signed certificate.\n\nThe previous defanging still issued real (loopback) HTTP requests to the CVE API, whose responses produced misleading errors in the UI.\n\nThis change removes the HTTP requests altogether in test mode and feeds mock data directly to the response callbacks.\n\n### Documentation\n\nBoth the one-time setup steps and the per-run startup commands are documented in `README-ASF.md`, including the `openssl` one-liner for the self-signed certificate.\n\n* fix: move `conf-asf.json` to `conf.json`\n\n* fix: force-add `conf.js`\n\nThe file is in `.gitignore`\n\n* fix: indentation"
    },
    {
      "commit": "4f1aca49cb51e04d88a2443067121698092d2e04",
      "tree": "95430cc50ecfd84c5f8461c0c5f74905a5008f1e",
      "parents": [
        "fcb5b3e86772b8e2c826d289a108ae2d2580127b"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 16:11:31 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 16:11:31 2026 +0200"
      },
      "message": "serverity level validation\n"
    },
    {
      "commit": "fcb5b3e86772b8e2c826d289a108ae2d2580127b",
      "tree": "c19de1f033649d34e51ae84e2d41e40dc7ed4266",
      "parents": [
        "5f7ecce309d4e5b6c713635f57c6791be1725c25"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 14:32:24 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 14:32:24 2026 +0200"
      },
      "message": "enable packageURL field\n"
    },
    {
      "commit": "5f7ecce309d4e5b6c713635f57c6791be1725c25",
      "tree": "6759046f0b5887d6848a4bd385cca0743f04313f",
      "parents": [
        "cd818987b805a5555ee73c0b7b7ede000ad1ad22",
        "f9b38520c4251c9114096e585dc796e861097d96"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 14:16:56 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 14:16:56 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027upstream/1.0.3\u0027 into integrate-upstream-changes\n"
    },
    {
      "commit": "cd818987b805a5555ee73c0b7b7ede000ad1ad22",
      "tree": "e96344246ebaea7e56934eec506665260af0a273",
      "parents": [
        "3a0ce91aeed21d5fac2ce8bb308502d7e09981c0",
        "184ccb9964add092b7d553f291ecda0bece30831"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 14:10:28 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 14:10:28 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027origin/main\u0027 into integrate-upstream-changes\n"
    },
    {
      "commit": "3a0ce91aeed21d5fac2ce8bb308502d7e09981c0",
      "tree": "ef0869835c80cb75c30c1529ecaea6a36420d353",
      "parents": [
        "5418adaa91a7bf7a8261446b6768639168067aa3",
        "9954795127cd1e5c7bbd05b2ac1f8fc2182762a3"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 05 12:16:27 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu May 07 14:09:42 2026 +0200"
      },
      "message": "Merge remote-tracking branch \u0027upstream/1.0.2\u0027 into integrate-upstream-changes\n"
    },
    {
      "commit": "184ccb9964add092b7d553f291ecda0bece30831",
      "tree": "0357d50c516a5d656a4b992954254e43d432e935",
      "parents": [
        "767dcdc0dda4571ba868c3824e85f36bae446f82"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed May 06 19:42:25 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 19:42:25 2026 +0200"
      },
      "message": "Bump actions/checkout from 2 to 6 (#192)\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 2 to 6.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v2...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: \u00276\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "767dcdc0dda4571ba868c3824e85f36bae446f82",
      "tree": "cb82eb9470bc3cda1766616e91380505d69fbf63",
      "parents": [
        "f0daa30db7e33c6ff694aefd72eaef07a25b28c9"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 19:21:22 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 19:21:22 2026 +0200"
      },
      "message": "Fix and simplify CodeQL action (#190)\n\nThis change:\n\n- adds the missing `security-events: write` permission to upload results,\n- simplifies the workflow by reducing it to a single workflow, without the unnecessary `autobuild` step."
    },
    {
      "commit": "f0daa30db7e33c6ff694aefd72eaef07a25b28c9",
      "tree": "794e6fc9fc35c6cb11dbf036d317f7b83dbc272b",
      "parents": [
        "38d73e2484b4c51f517261d744a31e32dee78dcb"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 18:57:59 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 18:57:59 2026 +0200"
      },
      "message": "Fix `dependabot.yml` syntax\n"
    },
    {
      "commit": "f9b38520c4251c9114096e585dc796e861097d96",
      "tree": "b23d7b2cd04f1b37f467e8487b87d7dca53962ce",
      "parents": [
        "c3759c8c40ea9d459a6334d0ea038e71cccae0bf"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed May 06 09:44:55 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed May 06 09:44:55 2026 -0700"
      },
      "message": "simplify message\n"
    },
    {
      "commit": "38d73e2484b4c51f517261d744a31e32dee78dcb",
      "tree": "d35b439f64392bd1b08c4bacebd3b9063881b9f5",
      "parents": [
        "4743f6ae71021161364aef9696da7a786f580cc1"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 14:26:59 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 14:26:59 2026 +0200"
      },
      "message": "Bump CodeQL to version 3\n\nThis is not the latest (which is version 4), but should be enough to\nrun. Dependabot should then update it to the latest.\n"
    },
    {
      "commit": "4743f6ae71021161364aef9696da7a786f580cc1",
      "tree": "b1b66c15ad75c7db0c7c04d304316c20f023f2e2",
      "parents": [
        "1df7c1ebe92e0725ab4424fd0e31f8212371608e"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 14:20:08 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 14:20:08 2026 +0200"
      },
      "message": "Try enabling Dependabot again\n\nA “Dependabot Updates\" shortly appeared, but Dependabot looks still\ndisabled.\n"
    },
    {
      "commit": "1df7c1ebe92e0725ab4424fd0e31f8212371608e",
      "tree": "32771952d7639f39d2e55b7577591ddfc4787912",
      "parents": [
        "a25df36ebc87393d8dbf4e9abb005c0e1de9aab0"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 14:16:33 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 14:16:33 2026 +0200"
      },
      "message": "Disable Dependabot for NPM\n"
    },
    {
      "commit": "a25df36ebc87393d8dbf4e9abb005c0e1de9aab0",
      "tree": "477e3f44be3bfdd5c221164cd8f8c4fe053ecfb5",
      "parents": [
        "5a603a48196cd6cc9a0462e513cd509ae195ad7d"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 14:07:43 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 14:07:43 2026 +0200"
      },
      "message": "Enable Dependabot (#188)\n\nThis change explicitly enables Dependabot Alerts and Updates on this repository, since they are apparently disabled."
    },
    {
      "commit": "5a603a48196cd6cc9a0462e513cd509ae195ad7d",
      "tree": "095e1edc6bf752e132023c9ac5d6ffaf53070856",
      "parents": [
        "8d48b5a917363db127fd7e998f45fc00ab274b49"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 13:22:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 13:22:42 2026 +0200"
      },
      "message": "Configure Dependabot for `github-actions` (#186)\n\nEnable weekly Dependabot updates for our workflow actions. PRs for `actions/*` and `github/*` are limited to major-version bumps, since those actions are referenced by their major tag (e.g. `@v4`) and so\nalready pick up minor and patch releases automatically."
    },
    {
      "commit": "8d48b5a917363db127fd7e998f45fc00ab274b49",
      "tree": "d965cec35decb23363535d4f77fc88e24205e337",
      "parents": [
        "8396f85044699ef726c25b90068949a8cf9753c4"
      ],
      "author": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 13:16:16 2026 +0200"
      },
      "committer": {
        "name": "Piotr P. Karwasz",
        "email": "pkarwasz-github@apache.org",
        "time": "Wed May 06 13:16:16 2026 +0200"
      },
      "message": "Ignore IntelliJ IDEA/WebStorm files\n"
    },
    {
      "commit": "8396f85044699ef726c25b90068949a8cf9753c4",
      "tree": "ee5d85827958f362427a93c9b91f85d35a7db793",
      "parents": [
        "2bbedb5e8b41200696bde8dc8e531aef09407cab"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Wed May 06 12:09:25 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 06 12:09:25 2026 +0200"
      },
      "message": "chore: restrict codeql CI permissions (#185)"
    },
    {
      "commit": "c3759c8c40ea9d459a6334d0ea038e71cccae0bf",
      "tree": "95d8bcfc62a10dad52d5c3e76d5dccb5af29d540",
      "parents": [
        "9954795127cd1e5c7bbd05b2ac1f8fc2182762a3"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed May 06 00:10:51 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed May 06 00:10:51 2026 -0700"
      },
      "message": "CVE Transfer Feature\n"
    },
    {
      "commit": "2bbedb5e8b41200696bde8dc8e531aef09407cab",
      "tree": "d5157664ddd2bf4e68097c761c10500291622bd4",
      "parents": [
        "1446fa65581672bfcea9de10e168986429aec3ac",
        "3700467d55e9e179b988e8ddac28272971c50f94"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "engelen@apache.org",
        "time": "Tue May 05 13:02:15 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 13:02:15 2026 +0200"
      },
      "message": "Merge pull request #181 from raboof/asf-dev-mode\n\nASF: disable CVE and email in \u0027development\u0027 mode"
    },
    {
      "commit": "3700467d55e9e179b988e8ddac28272971c50f94",
      "tree": "b7371532ee718155f5cac646b2a4eb8a857d0e30",
      "parents": [
        "df2f654b936aa2ab8fbde314a8e838d7ebcc50a5"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Mon May 04 11:37:42 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Tue May 05 13:00:49 2026 +0200"
      },
      "message": "ASF: disable CVE and email in \u0027development\u0027 mode\n"
    },
    {
      "commit": "9954795127cd1e5c7bbd05b2ac1f8fc2182762a3",
      "tree": "ca86e8d4cd405cbc27bc5384dcb0d820b7331de8",
      "parents": [
        "165d2b3a7024c1c176de2870de6e619abaf4d645"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 27 14:48:08 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 27 14:48:08 2026 -0700"
      },
      "message": "AV icons\n"
    },
    {
      "commit": "165d2b3a7024c1c176de2870de6e619abaf4d645",
      "tree": "43ea66cb5e259e2f8a32257935f33686f82c8073",
      "parents": [
        "2f11bcad931398f962666d21a4151e7b512924f0"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 27 13:45:19 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 27 13:45:19 2026 -0700"
      },
      "message": "missing spaces in html to text and the start of \u003cp\u003e\n"
    },
    {
      "commit": "1446fa65581672bfcea9de10e168986429aec3ac",
      "tree": "ce95af8d8ebde2300d2b1732195bd89100fdeda9",
      "parents": [
        "df2f654b936aa2ab8fbde314a8e838d7ebcc50a5",
        "ba78ab3fe3473fdf00b41337996960e161b8297d"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Thu Apr 16 14:03:41 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 16 14:03:41 2026 +0200"
      },
      "message": "Merge pull request #180 from raboof/allow-security-to-open-malformed-cves\n\nAllow security team members to edit malformed CVEs"
    },
    {
      "commit": "ba78ab3fe3473fdf00b41337996960e161b8297d",
      "tree": "ce95af8d8ebde2300d2b1732195bd89100fdeda9",
      "parents": [
        "df2f654b936aa2ab8fbde314a8e838d7ebcc50a5"
      ],
      "author": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 16 13:44:20 2026 +0200"
      },
      "committer": {
        "name": "Arnout Engelen",
        "email": "arnout@bzzt.net",
        "time": "Thu Apr 16 13:44:20 2026 +0200"
      },
      "message": "Allow security team members to edit malformed CVEs\n\nMuch easier than connecting to the db directly\n\nHappened for https://cveprocess.apache.org/cve5/CVE-2026-38743\n"
    },
    {
      "commit": "2f11bcad931398f962666d21a4151e7b512924f0",
      "tree": "563f2bc0e765165af20222a716c69ebac7c14850",
      "parents": [
        "22c231f227eabdaeb2f6d1727338499d629e3bca"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 13 00:25:46 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 13 00:25:46 2026 -0700"
      },
      "message": "set current time on focus - seems like the best option to address Firefox\u0027s lack of time picker on datetime-local\n"
    },
    {
      "commit": "22c231f227eabdaeb2f6d1727338499d629e3bca",
      "tree": "20778942cd5fa5195ac2d2272a4644f8d1ae16dc",
      "parents": [
        "f3ca0939b9db6da9c48ef2a918a1ab11f9d9d6a7"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 13 00:06:12 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Mon Apr 13 00:06:12 2026 -0700"
      },
      "message": "render improvements\n"
    },
    {
      "commit": "f3ca0939b9db6da9c48ef2a918a1ab11f9d9d6a7",
      "tree": "c61e3b79fc99255569124a365af90c688d0942ce",
      "parents": [
        "e66194edd6c762df8e079f9eb4519c2021185e99"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Sun Apr 12 23:23:44 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Sun Apr 12 23:23:44 2026 -0700"
      },
      "message": "Bug fixes, improve error bubble display, date rendering\n"
    },
    {
      "commit": "e66194edd6c762df8e079f9eb4519c2021185e99",
      "tree": "5a9c1e7e2f53d9f3fba0439b294aab819610ff71",
      "parents": [
        "cc2ac3b2dc274513b44a11c8ff32f78bcae58d4a"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Thu Apr 02 21:02:17 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Thu Apr 02 21:02:17 2026 -0700"
      },
      "message": "fix friendly date rendering\n"
    },
    {
      "commit": "cc2ac3b2dc274513b44a11c8ff32f78bcae58d4a",
      "tree": "9750bf2ae03bffbb3c5e9039cf3261626810d205",
      "parents": [
        "1a7cd00881805edc83192344c40911f844aff727"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Thu Apr 02 14:13:51 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Thu Apr 02 14:13:51 2026 -0700"
      },
      "message": "Bug fixes\n\n- set session timeout 6 hours. Added \u0027Remember me\u0027 option.\n- better preview workflow\n- fix error highlighting\n"
    },
    {
      "commit": "1a7cd00881805edc83192344c40911f844aff727",
      "tree": "1bf4fc6c4bb592dbc2730f2be0c06f176a108d43",
      "parents": [
        "f96bbdf6ed3cd9868428b234b7debf3af5585d39"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed Apr 01 13:37:11 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed Apr 01 13:37:11 2026 -0700"
      },
      "message": "bug fixes, don\u0027t invert colors for some icons like logos\n"
    },
    {
      "commit": "f96bbdf6ed3cd9868428b234b7debf3af5585d39",
      "tree": "b1860bd1d31a2a9b7650c2201addb2859fe0e58b",
      "parents": [
        "f99dd545d2bc972f210a243b1e21880af30171bf"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed Apr 01 00:09:58 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Wed Apr 01 00:09:58 2026 -0700"
      },
      "message": "fix loading isse when there was no session\n"
    },
    {
      "commit": "f99dd545d2bc972f210a243b1e21880af30171bf",
      "tree": "a7ee3833f3ac2b0c87820716ddee1f6b4a8abac5",
      "parents": [
        "f7d2419cf126ec59a21b461ab6c62ee9ff14b4e8",
        "cc9a3279aa64ab56f467c1c0a805c9e55512a70c"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Tue Mar 31 23:39:06 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 31 23:39:06 2026 -0700"
      },
      "message": "Merge pull request #306 from Vulnogram/master\n\nBring in changes from main"
    },
    {
      "commit": "f7d2419cf126ec59a21b461ab6c62ee9ff14b4e8",
      "tree": "e949f028c7f696492181345aecbfbc40bd8727cd",
      "parents": [
        "85c8fcae2222718bebdc95f7f5dcb7b22ccf13b9"
      ],
      "author": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Tue Mar 31 23:37:58 2026 -0700"
      },
      "committer": {
        "name": "Chandan",
        "email": "chandanbn@gmail.com",
        "time": "Tue Mar 31 23:37:58 2026 -0700"
      },
      "message": "bug fixes\n"
    }
  ],
  "next": "85c8fcae2222718bebdc95f7f5dcb7b22ccf13b9"
}
