{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://uc.surf/data/findings/schema.json",
  "title": "ucsurf OSS finding",
  "type": "object",
  "additionalProperties": true,
  "required": [
    "id",
    "title",
    "category",
    "type",
    "severity",
    "ecosystem",
    "project",
    "status",
    "summary",
    "discovered_at",
    "updated_at",
    "public",
    "credit"
  ],
  "properties": {
    "id": {
      "type": "string",
      "description": "Stable id derived from path: category/ecosystem/owner__repo/YYYY-MM-DD-slug"
    },
    "title": { "type": "string" },
    "category": {
      "type": "string",
      "enum": ["security", "bugs", "docs", "performance"]
    },
    "type": {
      "type": "string",
      "description": "e.g. dos, auth-bypass, injection, crash, logic-bug"
    },
    "severity": {
      "type": "string",
      "enum": ["critical", "high", "medium", "low", "info"]
    },
    "cvss": {
      "oneOf": [
        { "type": "null" },
        {
          "type": "object",
          "properties": {
            "vector": { "type": ["string", "null"] },
            "score": { "type": ["number", "null"] },
            "notes": { "type": "string" }
          }
        }
      ]
    },
    "ecosystem": {
      "type": "string",
      "description": "rust, go, python, javascript, php, ruby, java, c, ..."
    },
    "project": {
      "type": "object",
      "required": ["owner", "repo", "url"],
      "properties": {
        "owner": { "type": "string" },
        "repo": { "type": "string" },
        "url": { "type": "string", "format": "uri" }
      }
    },
    "affected_versions": {
      "oneOf": [
        { "type": "null" },
        { "type": "array", "items": { "type": "string" } },
        { "type": "string" }
      ]
    },
    "status": {
      "type": "string",
      "enum": [
        "found",
        "reported",
        "triaged",
        "accepted",
        "fixed",
        "published",
        "rejected",
        "duplicate",
        "closed"
      ]
    },
    "disclosure": {
      "oneOf": [
        { "type": "null" },
        {
          "type": "object",
          "properties": {
            "channel": {
              "type": "string",
              "enum": ["pvr", "email", "public-issue", "pr"]
            },
            "ghsa_id": { "type": ["string", "null"] },
            "cve_id": { "type": ["string", "null"] },
            "url": { "type": ["string", "null"] },
            "reported_at": { "type": ["string", "null"], "format": "date-time" },
            "published_at": { "type": ["string", "null"], "format": "date-time" }
          }
        }
      ]
    },
    "pr": {
      "oneOf": [
        { "type": "null" },
        {
          "type": "object",
          "properties": {
            "url": { "type": "string" },
            "state": { "type": "string" },
            "merged_at": { "type": ["string", "null"] },
            "number": { "type": "integer" },
            "issue": { "type": "integer" }
          }
        }
      ]
    },
    "summary": { "type": "string", "description": "Short plain-language summary" },
    "discovered_at": { "type": "string", "format": "date-time" },
    "updated_at": { "type": "string", "format": "date-time" },
    "public": {
      "type": "boolean",
      "description": "true only if advisory published, or it is a public issue/PR"
    },
    "credit": { "type": "string", "const": "ucsurf" },
    "sources": {
      "type": "array",
      "items": { "type": "string" },
      "description": "Internal source paths used when populating (private DB only)"
    },
    "notes": { "type": "string" }
  }
}
