Skip to content

Merge 1.0.0-beta to int - #161

Merged
jdaigneau5 merged 21 commits into
intfrom
test
Oct 1, 2026
Merged

jdaigneau5 merged 21 commits into
intfrom
test

Conversation

@afoote-mitre

Copy link
Copy Markdown
Collaborator

Summary

Merge the current dev branch to test for the 1.0.0-beta release.

Consumer And Deployment Changes

  • /search success responses now contain apiVersion, status, warnings, pagination, and records. Consumers must read complete CVE Records from records and pagination metadata from pagination, rather than the previous OpenSearch-backed response structure.
  • Warnings appear before records. Reaching the semantic candidate cap sets pagination.totalIsExact to false; totals and pages then describe only the inspected candidate set.
  • Pre-1999 CVE IDs remain accepted and produce a warning without preventing other requested IDs from returning matches.
  • Invalid CPE inputs return HTTP 400 with specific validation guidance. cpeName requires concrete part, vendor, product, and version components; embedded unescaped wildcards in these components are rejected. virtualMatchString requires a CPE prefix and valid part component, while supported broad searches remain available with warnings.
  • SearchLogPerformanceTimings and SearchPerformanceTelemetryIntervalMs no longer control application behavior. Their configuration mappings and the in-process telemetry implementation are removed; request correlation and access logging remain.

Why These Changes Were Needed

Change Why It Was Needed Primary Files
Introduce an API-owned search response Exposing OpenSearch hit wrappers coupled consumers to the backend and exposed transport metadata such as index names and timing. A dedicated response builder returns full CVE Records, keeps requested page size separate from returned count, and provides explicit total-accuracy metadata. utils/searchResponseBuilder.js, controllers/searchController.js, routes/swagger.js, api-docs/openapi.json
Explain non-fatal search limitations Users needed visible explanations for unsupported historical CVE years, broad CPE searches, omitted CPE components, and bounded semantic results without turning valid searches into errors. Warnings precede records in the response. utils/searchResponseBuilder.js, utils/constants.js, utils/cpe.js, routes/swagger.js, README.md
Strengthen CPE input validation Malformed names and partial wildcard versions could be interpreted as literal versions and return misleading matches. Shared parsing now validates component counts, part values, empty components, whitespace, and escapes; required cpeName components reject unescaped * and ?. utils/cpe.js, controllers/middleware.js, utils/errors.js, routes/swagger.js
Preserve escaped CPE components in candidate queries The escape-aware parser did not prevent wildcard candidate patterns from stopping at an escaped colon inside a stored component. Valid records could be excluded before semantic matching. Candidate patterns now preserve escaped characters while recognizing actual component separators. utils/cpe.js, utils/cpe.test.js, utils/searchQueryBuilder.test.js, controllers/searchController.test.js
Reject empty stored version intervals Overlap checks could accept an inverted stored interval or an equal-bound interval with an exclusive endpoint. Each interval is now checked for validity before overlap is evaluated. utils/cpe.js, utils/cpe.test.js, README.md
Enforce semantic-search deadlines cooperatively Synchronous filtering could delay the timeout callback, allowing expired work to continue. Monotonic elapsed-time checks now run between candidates and after filtering, and filtering yields every 100 candidates so cancellation can be processed. This does not preempt an individual synchronous operation. utils/searchDeadline.js, utils/searchPostFilters.js, controllers/searchController.js, corresponding regression files
Reject conflicting mapped field types during readiness A compatible type in one index could hide an incompatible type for the same field in another index behind an alias. All reported mapped types for checked fields must satisfy the required type, searchability, and aggregation capabilities. utils/searchReadiness.js, utils/searchReadiness.test.js, utils/searchProvider.test.js, README.md
Honor Postman environment-level fault settings The collection previously ignored the documented environment-level opt-in. An explicitly configured environment value now takes precedence over the collection value, and only the string true enables manual fault requests. test/postman/buildCollection.js, test/postman/CVE-Search-API.postman_collection.json, test/postman/collection.test.js, test/postman/README.md
Sanitize terminal parser and server errors Falling through to Express's default error handler could return HTML and expose exception details in development. Unsent error responses now use sanitized JSON for oversized bodies, unsupported encodings, unreadable bodies, and unexpected server errors. Existing malformed-JSON and /search content-type responses are retained. server.js, utils/errors.js, server.test.js, routes/index.js, api-docs/openapi.json
Bound timeout configuration to Node's timer range Excessively large values can overflow timers and produce unexpectedly immediate timeouts. Readiness, OpenSearch-request, and overall-search timeouts now accept integer values from 1 through 2,147,483,647 milliseconds and fall back to existing defaults otherwise. utils/constants.js, utils/searchProvider.js, utils/searchProvider.test.js, README.md
Remove in-process performance telemetry Public-release code should focus on API behavior rather than the temporary diagnostic implementation. Timing aggregation, process-resource telemetry, controller instrumentation, and related settings are removed while search deadlines and operational access logs remain. Deleted utils/searchPerformanceTelemetry.js and its test file; controllers/searchController.js, config/default.jsonc, config/custom-environment-variables.jsonc, .env.example
Update dependency versions Incorporates the dependency remediation updates already merged into dev: Morgan moves from ~1.11.0 to ~1.12.0, and the js-yaml override moves from 4.3.1 to 4.3.2. package.json, package-lock.json
Align documentation and client artifacts Setup, readiness, scope exclusions, keyword phrase/prefix behavior, raw-query sorting, logging sampling, and pagination guidance needed to reflect actual behavior. OpenAPI descriptions and the Postman collection now reflect the response and validation changes; duplicate raw-query HTTP 400 declarations were consolidated during the merge from dev. README.md, routes/index.js, routes/swagger.js, api-docs/openapi.json, test/postman/README.md, test/postman/buildCollection.js, generated Postman collection, configuration comments

afoote-mitre and others added 21 commits September 10, 2026 11:05
Define a stable public search response contract
Strengthen CPE validation and remove search telemetry
Fix embedded wildcard validation in cpeName searches
docs: align API documentation with current behavior
Fix CPE matching, search deadlines, and review findings
Merge 1.0.0-beta to test
@afoote-mitre afoote-mitre self-assigned this Oct 1, 2026
@jdaigneau5
jdaigneau5 merged commit ec3496c into int Oct 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants