{ "_comment": "Offline advisory fixture for dependency-cve.sh --canary (and --advisories-file). This stands in for the live OSV querybatch API so the canary is fully offline + deterministic. Each entry is keyed by 'ECOSYSTEM|package|version' (ECOSYSTEM matches OSV ecosystem names: PyPI, npm, NuGet) and carries the fields the checker emits in a finding's proof. These mirror REAL advisories (GHSA/CVE ids + summaries + fixed versions) so the fixture is realistic, but the checker NEVER reaches the network in canary mode — it reads only this file.", "advisories": { "PyPI|jinja2|2.11.2": [ { "id": "GHSA-g3rq-g295-4j3m", "summary": "Jinja2 ReDoS in the urlize filter via the urlize regex", "severity": "high", "cvss": 7.5, "fixed_version": "2.11.3" } ], "npm|lodash|4.17.15": [ { "id": "GHSA-p6mc-m468-83gw", "summary": "Prototype pollution in lodash (zipObjectDeep / set / setWith)", "severity": "high", "cvss": 7.4, "fixed_version": "4.17.19" } ] } }