From d72600ec22fa003fee284af0a0b9aa9d90ec4119 Mon Sep 17 00:00:00 2001 From: Andrew Foote Date: Tue, 6 Oct 2026 09:40:23 -0400 Subject: [PATCH 1/2] Add Search API project and contribution documentation --- CODE_OF_CONDUCT.md | 76 ++++++++++++++++++++++++ CONTRIBUTING.md | 116 +++++++++++++++++++++++++++++++++++++ LICENSE | 121 +++++++++++++++++++++++++++++++++++++++ PULL_REQUEST_TEMPLATE.md | 25 ++++++++ README.md | 47 +++++++++++++++ SECURITY.md | 39 +++++++++++++ 6 files changed, 424 insertions(+) create mode 100644 CODE_OF_CONDUCT.md create mode 100644 CONTRIBUTING.md create mode 100644 LICENSE create mode 100644 PULL_REQUEST_TEMPLATE.md create mode 100644 SECURITY.md diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..6fa4681 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,76 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +In the interest of fostering an open and welcoming environment, we as +contributors and maintainers pledge to making participation in our project and +our community a harassment-free experience for everyone, regardless of age, body +size, disability, ethnicity, sex characteristics, gender identity and expression, +level of experience, education, socio-economic status, nationality, personal +appearance, race, religion, or sexual identity and orientation. + +## Our Standards + +Examples of behavior that contributes to creating a positive environment +include: + +- Using welcoming and inclusive language +- Being respectful of differing viewpoints and experiences +- Gracefully accepting constructive criticism +- Focusing on what is best for the community +- Showing empathy towards other community members + +Examples of unacceptable behavior by participants include: + +- The use of sexualized language or imagery and unwelcome sexual attention or + advances +- Trolling, insulting/derogatory comments, and personal or political attacks +- Public or private harassment +- Publishing others' private information, such as a physical or electronic + address, without explicit permission +- Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Our Responsibilities + +Project maintainers are responsible for clarifying the standards of acceptable +behavior and are expected to take appropriate and fair corrective action in +response to any instances of unacceptable behavior. + +Project maintainers have the right and responsibility to remove, edit, or +reject comments, commits, code, wiki edits, issues, and other contributions +that are not aligned to this Code of Conduct, or to ban temporarily or +permanently any contributor for other behaviors that they deem inappropriate, +threatening, offensive, or harmful. + +## Scope + +This Code of Conduct applies both within project spaces and in public spaces +when an individual is representing the project or its community. Examples of +representing a project or community include using an official project e-mail +address, posting via an official social media account, or acting as an appointed +representative at an online or offline event. Representation of a project may be +further defined and clarified by project maintainers. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported by contacting the project team at mbianchi@mitre.org. All +complaints will be reviewed and investigated and will result in a response that +is deemed necessary and appropriate to the circumstances. The project team is +obligated to maintain confidentiality with regard to the reporter of an incident. +Further details of specific enforcement policies may be posted separately. + +Project maintainers who do not follow or enforce the Code of Conduct in good +faith may face temporary or permanent repercussions as determined by other +members of the project's leadership. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4, +available at https://www.contributor-covenant.org/version/1/4/code-of-conduct.html + +[homepage]: https://www.contributor-covenant.org + +For answers to common questions about this code of conduct, see +https://www.contributor-covenant.org/faq diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..de49ce3 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,116 @@ +# Contributing to CVE Search API + +Thank you for considering contributions to the CVE Search API and the CVE Project's Automation Working Group! + +The following is a set of guidelines for contributing. In general, use your best judgement, and feel free to propose changes to this document in a pull request. + +## Table of Contents + +- [Code of Conduct](#code-of-conduct) +- [I just have a question](#i-just-have-a-question) +- [How Can I Contribute?](#how-can-i-contribute) + - [Reporting Bugs](#reporting-bugs) + - [Code Proposals](#code-proposals) + - [Pull Requests](#pull-requests) +- [Style Guides](#style-guides) + - [Git Commit Messages](#git-commit-messages) + - [JavaScript Style Guide](#javascript-style-guide) + +## Code of Conduct + +Contributors to this project are governed by the [Code of Conduct](CODE_OF_CONDUCT.md). By participating, you are expected to uphold this code. Please report unacceptable behavior via email to the AWG Chair at rbritton@mitre.org. + +## I just have a question + +Start with the [README](README.md) and its [API documentation guidance](README.md#swagger-api-docs). For other questions or help finding the appropriate community discussion channel, email the AWG Chair at rbritton@mitre.org. + +## How Can I Contribute? + +### Reporting Bugs + +This section guides you through submitting a bug report. Following these guidelines helps maintainers and the community understand your report, reproduce the behavior, and find related reports. + +Before creating bug reports, please check [existing reports](#before-submitting-a-bug-report). When creating a report, please [include the details below](#how-do-i-submit-a-good-bug-report) to help us reproduce and resolve the issue. + +> [!WARNING] +> Do not report security vulnerabilities in public issues or pull requests. Follow the private reporting instructions in [SECURITY.md](SECURITY.md). + +> **Note:** +> If you find a **Closed** issue that seems like it is the same thing that you're experiencing, open a new issue and include a link to the original issue in the body of your new one. + +#### Before Submitting A Bug Report + +**Search the [open issues](https://github.com/CVEProject/CVE-Search-API/issues?q=is%3Aopen+is%3Aissue)** to see if the problem has already been reported. If it has **and the issue is still open**, add a comment to the existing issue instead of opening a new one. + +#### How Do I Submit A (Good) Bug Report? + +Bugs are tracked in the [CVE Search API issue tracker](https://github.com/CVEProject/CVE-Search-API/issues). Include the following information in your report. + +Explain the problem and include additional details to help maintainers reproduce the problem: + +- **Use a clear and descriptive title** for the issue to identify the problem. +- **Describe the exact steps that reproduce the problem**. Include how you started or accessed the API, the endpoint and HTTP method, and a minimal request body or curl command. Remove credentials, private deployment URLs, and other sensitive information before sharing examples or logs. +- **Provide specific examples to demonstrate the steps**. Include links to files or GitHub projects, or copy/pasteable snippets, which you use in those examples. If you're providing snippets in the issue, use [Markdown code blocks](https://help.github.com/articles/markdown-basics/#multiple-lines). +- **Describe the behavior you observed after following the steps** and point out what exactly is the problem with that behavior. +- **Explain which behavior you expected to see instead and why.** +- **If the problem wasn't triggered by a specific action**, describe what you were doing before the problem happened and share more information using the guidelines below. + +Provide more context by answering these questions: + +- **Can you reliably reproduce the issue?** If not, provide details about how often the problem happens and under which conditions it normally happens. + +Include details about your configuration and environment: + +- **Which version of the API are you using?** +- **What's the name and version of the OS you're using**? +- **Are you running with npm or Docker, and which Node.js and OpenSearch versions are involved?** +- **Does the index contain the CVE Records and fields needed to reproduce the issue?** An incomplete local index can produce different results from a fully populated deployment. + +### Code Proposals + +This section guides you through submitting a code proposal for the CVE Search API, including completely new features and minor improvements to existing functionality. Following these guidelines helps maintainers and the community understand your proposal and find related suggestions. + +Before creating a code proposal, please check the [open issues](https://github.com/CVEProject/CVE-Search-API/issues?q=is%3Aopen+is%3Aissue) for related suggestions. Describe the use case and the steps you would take if the proposed feature existed, using the guidance below. + +#### How Do I Submit A (Good) Code Proposal? + +Enhancement suggestions are tracked in the [CVE Search API issue tracker](https://github.com/CVEProject/CVE-Search-API/issues). Please make sure to provide the following information: + +- **Use a clear and descriptive title** for the issue to identify the suggestion. +- **Provide a step-by-step description of the suggested enhancement** in as many details as possible. +- **Provide specific examples to demonstrate the steps when applicable**. Include copy/paste-able snippets which you use in those examples, as [Markdown code blocks](https://help.github.com/articles/markdown-basics/#multiple-lines). +- **Describe the current behavior** and **explain which behavior you expected to see instead** and why (if applicable). +- **Explain why this enhancement would be useful** to most users and isn't something that can or should be implemented as an outside service that just integrates with the API. + +### Pull Requests + +The process described here has several goals: + +- Maintain quality +- Fix problems that are important to users +- Engage the community in working toward the best possible solutions +- Enable a sustainable system for maintainers to review contributions + +Please follow these steps to have your contribution considered by the maintainers: + +1. Follow the instructions in [the template](PULL_REQUEST_TEMPLATE.md) +2. Follow the [style guides](#style-guides) +3. After you submit a pull request, verify that all [status checks](https://help.github.com/articles/about-status-checks/) pass
What if the status checks fail?If a status check fails and you believe that the failure is unrelated to your change, please leave a comment explaining why. If the failure was a false positive, a reviewer will open an issue to track that problem with the status check suite.
+ +> **Note** +> A reviewer may ask you to complete additional design work, tests, or other changes before your pull request is accepted. + +## Style Guides + +### Git Commit Messages + +- Begin the message with the issue number, for example: "#123 this is the commit message". (Git CLI users should specify the message as a flag: `git commit -m "#123 message"` or change the [core.commentchar](https://git-scm.com/docs/git-config#Documentation/git-config.txt-corecommentChar) value.) +- Use the present tense ("Add feature" not "Added feature") +- Use the imperative mood ("Add filter..." not "Adds filter...") +- Limit the first line to 72 characters or less + +### JavaScript Style Guide + +Follow the repository's [ESLint configuration](eslint.config.js) and [Prettier configuration](.prettierrc.json), and prefer existing code patterns. Use `npm run lint` and `npm run format:check` to check style; `npm run lint:fix` and `npm run format` apply fixes. Review their changes before committing. + +The combined `npm run quality` command runs linting, formatting checks, and the Jest suite with coverage thresholds. See the [README testing section](README.md#testing) for the available checks. diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..0e259d4 --- /dev/null +++ b/LICENSE @@ -0,0 +1,121 @@ +Creative Commons Legal Code + +CC0 1.0 Universal + + CREATIVE COMMONS CORPORATION IS NOT A LAW FIRM AND DOES NOT PROVIDE + LEGAL SERVICES. DISTRIBUTION OF THIS DOCUMENT DOES NOT CREATE AN + ATTORNEY-CLIENT RELATIONSHIP. CREATIVE COMMONS PROVIDES THIS + INFORMATION ON AN "AS-IS" BASIS. CREATIVE COMMONS MAKES NO WARRANTIES + REGARDING THE USE OF THIS DOCUMENT OR THE INFORMATION OR WORKS + PROVIDED HEREUNDER, AND DISCLAIMS LIABILITY FOR DAMAGES RESULTING FROM + THE USE OF THIS DOCUMENT OR THE INFORMATION OR WORKS PROVIDED + HEREUNDER. + +Statement of Purpose + +The laws of most jurisdictions throughout the world automatically confer +exclusive Copyright and Related Rights (defined below) upon the creator +and subsequent owner(s) (each and all, an "owner") of an original work of +authorship and/or a database (each, a "Work"). + +Certain owners wish to permanently relinquish those rights to a Work for +the purpose of contributing to a commons of creative, cultural and +scientific works ("Commons") that the public can reliably and without fear +of later claims of infringement build upon, modify, incorporate in other +works, reuse and redistribute as freely as possible in any form whatsoever +and for any purposes, including without limitation commercial purposes. +These owners may contribute to the Commons to promote the ideal of a free +culture and the further production of creative, cultural and scientific +works, or to gain reputation or greater distribution for their Work in +part through the use and efforts of others. + +For these and/or other purposes and motivations, and without any +expectation of additional consideration or compensation, the person +associating CC0 with a Work (the "Affirmer"), to the extent that he or she +is an owner of Copyright and Related Rights in the Work, voluntarily +elects to apply CC0 to the Work and publicly distribute the Work under its +terms, with knowledge of his or her Copyright and Related Rights in the +Work and the meaning and intended legal effect of CC0 on those rights. + +1. Copyright and Related Rights. A Work made available under CC0 may be +protected by copyright and related or neighboring rights ("Copyright and +Related Rights"). Copyright and Related Rights include, but are not +limited to, the following: + + i. the right to reproduce, adapt, distribute, perform, display, + communicate, and translate a Work; + ii. moral rights retained by the original author(s) and/or performer(s); +iii. publicity and privacy rights pertaining to a person's image or + likeness depicted in a Work; + iv. rights protecting against unfair competition in regards to a Work, + subject to the limitations in paragraph 4(a), below; + v. rights protecting the extraction, dissemination, use and reuse of data + in a Work; + vi. database rights (such as those arising under Directive 96/9/EC of the + European Parliament and of the Council of 11 March 1996 on the legal + protection of databases, and under any national implementation + thereof, including any amended or successor version of such + directive); and +vii. other similar, equivalent or corresponding rights throughout the + world based on applicable law or treaty, and any national + implementations thereof. + +2. Waiver. To the greatest extent permitted by, but not in contravention +of, applicable law, Affirmer hereby overtly, fully, permanently, +irrevocably and unconditionally waives, abandons, and surrenders all of +Affirmer's Copyright and Related Rights and associated claims and causes +of action, whether now known or unknown (including existing as well as +future claims and causes of action), in the Work (i) in all territories +worldwide, (ii) for the maximum duration provided by applicable law or +treaty (including future time extensions), (iii) in any current or future +medium and for any number of copies, and (iv) for any purpose whatsoever, +including without limitation commercial, advertising or promotional +purposes (the "Waiver"). Affirmer makes the Waiver for the benefit of each +member of the public at large and to the detriment of Affirmer's heirs and +successors, fully intending that such Waiver shall not be subject to +revocation, rescission, cancellation, termination, or any other legal or +equitable action to disrupt the quiet enjoyment of the Work by the public +as contemplated by Affirmer's express Statement of Purpose. + +3. Public License Fallback. Should any part of the Waiver for any reason +be judged legally invalid or ineffective under applicable law, then the +Waiver shall be preserved to the maximum extent permitted taking into +account Affirmer's express Statement of Purpose. In addition, to the +extent the Waiver is so judged Affirmer hereby grants to each affected +person a royalty-free, non transferable, non sublicensable, non exclusive, +irrevocable and unconditional license to exercise Affirmer's Copyright and +Related Rights in the Work (i) in all territories worldwide, (ii) for the +maximum duration provided by applicable law or treaty (including future +time extensions), (iii) in any current or future medium and for any number +of copies, and (iv) for any purpose whatsoever, including without +limitation commercial, advertising or promotional purposes (the +"License"). The License shall be deemed effective as of the date CC0 was +applied by Affirmer to the Work. Should any part of the License for any +reason be judged legally invalid or ineffective under applicable law, such +partial invalidity or ineffectiveness shall not invalidate the remainder +of the License, and in such case Affirmer hereby affirms that he or she +will not (i) exercise any of his or her remaining Copyright and Related +Rights in the Work or (ii) assert any associated claims and causes of +action with respect to the Work, in either case contrary to Affirmer's +express Statement of Purpose. + +4. Limitations and Disclaimers. + + a. No trademark or patent rights held by Affirmer are waived, abandoned, + surrendered, licensed or otherwise affected by this document. + b. Affirmer offers the Work as-is and makes no representations or + warranties of any kind concerning the Work, express, implied, + statutory or otherwise, including without limitation warranties of + title, merchantability, fitness for a particular purpose, non + infringement, or the absence of latent or other defects, accuracy, or + the present or absence of errors, whether or not discoverable, all to + the greatest extent permissible under applicable law. + c. Affirmer disclaims responsibility for clearing rights of other persons + that may apply to the Work or any use thereof, including without + limitation any person's Copyright and Related Rights in the Work. + Further, Affirmer disclaims responsibility for obtaining any necessary + consents, permissions or other rights required for any use of the + Work. + d. Affirmer understands and acknowledges that Creative Commons is not a + party to this document and has no duty or obligation with respect to + this CC0 or use of the Work. diff --git a/PULL_REQUEST_TEMPLATE.md b/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..5c1445f --- /dev/null +++ b/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,25 @@ +Note: Please format the pull request title like: +"Resolves issue ###, High level description of pull request." + +Closes Issue ### + +# Summary + +Write out a concise summary of this PR and its impact on the CVE Search API. + +# Important Changes + +`example_file.js` + +- Cleaned code and added comments. +- Added method to handle adding items. + +# Testing + +Steps to manually test updated functionality, if possible + +- [ ] 1) Example test step. + +# Notes + +- Some additional notes about this PR. diff --git a/README.md b/README.md index 30af149..6854015 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,52 @@ # CVE Search API +## Table of Contents + +- [The CVE Search API Project](#the-cve-search-api-project) + - [OSS Contributor](#oss-contributor) + - [Working Groups](#working-groups) + - [Security](#security) + - [Reporting a Vulnerability](#reporting-a-vulnerability) +- [Running the API locally](#running-the-api-locally) +- [Docker API Only](#docker-api-only) +- [Deploying with npm](#deploying-with-npm) +- [Health Checks](#health-checks) +- [API Input Validation](#api-input-validation) + - [CPE Name Search](#cpe-name-search) + - [Virtual Match String Search](#virtual-match-string-search) + - [Virtual Match String Version Ranges](#virtual-match-string-version-ranges) +- [Raw Query Endpoint](#raw-query-endpoint) +- [Swagger API docs](#swagger-api-docs) +- [Testing](#testing) +- [Operational Logging](#operational-logging) +- [Semantic Post-Filtering](#semantic-post-filtering) +- [Docker Runtime Checks](#docker-runtime-checks) + +## The CVE Search API Project + +This repository provides an API for searching CVE Records in an existing OpenSearch index. It supports the [CVE Program's mission](https://www.cve.org/About/Overview) to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities by making CVE Records searchable through structured filters and a raw-query endpoint. + +There are several ways to contribute to the project and the wider CVE community. + +### OSS Contributor + +Developers can contribute code, documentation, bug reports, and improvement proposals. Start by reviewing the [open issues](https://github.com/CVEProject/CVE-Search-API/issues?q=is%3Aissue+is%3Aopen), then read the [contribution guide](CONTRIBUTING.md) and [pull request template](PULL_REQUEST_TEMPLATE.md). We welcome contributions that improve the CVE Search API. + +All participants are expected to follow the [Code of Conduct](CODE_OF_CONDUCT.md). The project's license is [CC0 1.0 Universal](LICENSE). + +### Working Groups + +The CVE Program operates focused working groups. Visit the [working groups page](https://www.cve.org/ProgramOrganization/WorkingGroups) to learn how to participate in the broader program. + +### Security + +#### Reporting a Vulnerability + +> [!WARNING] +> Do not put vulnerability information in a public GitHub issue or pull request. + +Follow the [security policy](SECURITY.md) for instructions on privately reporting a vulnerability in the CVE Search API. + ## Running the API locally Copy `.env.example` to an untracked `.env` and replace or check the following values. Keep the tracked example in place. diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..4400c5d --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,39 @@ +# Security Policy + +- [Reporting a Vulnerability](#reporting-a-vulnerability) +- [Scope](#scope) +- [Fixes](#fixes) +- [Coordination](#coordination) + +## Reporting a Vulnerability + +Do not disclose vulnerability details in a public GitHub issue or pull request. + +Please report security vulnerabilities by going to the [CVE Program web forms](https://cveform.mitre.org/). Please include vulnerability details, steps to reproduce (e.g., proof-of-concept code, screenshots) and an assessment of the impact in your report. We appreciate concise and high quality reports. + +#### Web Form Guide + +- In the “Select a request type” drop down menu, please select “other” +- Enter your email address in the space provided +- You may enter a PGP key if you prefer to encrypt your correspondence +- In the “Type of comment” drop down menu, please select “Issue” +- In the textbox labeled “Please provide your question, issue, comment, etc.” please start the message with the following information: + - First Line: “CVE Search API Security Anomaly Report” + - Second Line: “Distribution: CVE Search API Development Team” + - Third Line: "Description: [Free Text description of the anomaly]” +- Enter the Security code +- Click “Submit Request” + +## Scope + +The API in the [CVE Search API repository](https://github.com/CVEProject/CVE-Search-API) is in scope for reporting vulnerabilities. + +## Fixes + +We will release fixes and assign CVE IDs for verified security vulnerabilities. We expect to publish vulnerabilities using GitHub [security advisories](https://github.com/CVEProject/CVE-Search-API/security/advisories). + +## Coordination + +We appreciate the opportunity to investigate and develop fixes before public disclosure, following coordinated vulnerability disclosure practices. + +For vulnerabilities that affect upstream dependencies, we can assist reporting and coordinating with the appropriate parties. We will not share your identification without your permission, but may share the other relevant parts of your report. From 704ccbdac1b96e5392afc4cba728b27ce93b1d7b Mon Sep 17 00:00:00 2001 From: Andrew Foote Date: Tue, 6 Oct 2026 09:56:53 -0400 Subject: [PATCH 2/2] Limit project documentation additions to license and README --- CODE_OF_CONDUCT.md | 76 ------------------------- CONTRIBUTING.md | 116 --------------------------------------- PULL_REQUEST_TEMPLATE.md | 25 --------- README.md | 26 +-------- SECURITY.md | 39 ------------- 5 files changed, 3 insertions(+), 279 deletions(-) delete mode 100644 CODE_OF_CONDUCT.md delete mode 100644 CONTRIBUTING.md delete mode 100644 PULL_REQUEST_TEMPLATE.md delete mode 100644 SECURITY.md diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md deleted file mode 100644 index 6fa4681..0000000 --- a/CODE_OF_CONDUCT.md +++ /dev/null @@ -1,76 +0,0 @@ -# Contributor Covenant Code of Conduct - -## Our Pledge - -In the interest of fostering an open and welcoming environment, we as -contributors and maintainers pledge to making participation in our project and -our community a harassment-free experience for everyone, regardless of age, body -size, disability, ethnicity, sex characteristics, gender identity and expression, -level of experience, education, socio-economic status, nationality, personal -appearance, race, religion, or sexual identity and orientation. - -## Our Standards - -Examples of behavior that contributes to creating a positive environment -include: - -- Using welcoming and inclusive language -- Being respectful of differing viewpoints and experiences -- Gracefully accepting constructive criticism -- Focusing on what is best for the community -- Showing empathy towards other community members - -Examples of unacceptable behavior by participants include: - -- The use of sexualized language or imagery and unwelcome sexual attention or - advances -- Trolling, insulting/derogatory comments, and personal or political attacks -- Public or private harassment -- Publishing others' private information, such as a physical or electronic - address, without explicit permission -- Other conduct which could reasonably be considered inappropriate in a - professional setting - -## Our Responsibilities - -Project maintainers are responsible for clarifying the standards of acceptable -behavior and are expected to take appropriate and fair corrective action in -response to any instances of unacceptable behavior. - -Project maintainers have the right and responsibility to remove, edit, or -reject comments, commits, code, wiki edits, issues, and other contributions -that are not aligned to this Code of Conduct, or to ban temporarily or -permanently any contributor for other behaviors that they deem inappropriate, -threatening, offensive, or harmful. - -## Scope - -This Code of Conduct applies both within project spaces and in public spaces -when an individual is representing the project or its community. Examples of -representing a project or community include using an official project e-mail -address, posting via an official social media account, or acting as an appointed -representative at an online or offline event. Representation of a project may be -further defined and clarified by project maintainers. - -## Enforcement - -Instances of abusive, harassing, or otherwise unacceptable behavior may be -reported by contacting the project team at mbianchi@mitre.org. All -complaints will be reviewed and investigated and will result in a response that -is deemed necessary and appropriate to the circumstances. The project team is -obligated to maintain confidentiality with regard to the reporter of an incident. -Further details of specific enforcement policies may be posted separately. - -Project maintainers who do not follow or enforce the Code of Conduct in good -faith may face temporary or permanent repercussions as determined by other -members of the project's leadership. - -## Attribution - -This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4, -available at https://www.contributor-covenant.org/version/1/4/code-of-conduct.html - -[homepage]: https://www.contributor-covenant.org - -For answers to common questions about this code of conduct, see -https://www.contributor-covenant.org/faq diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md deleted file mode 100644 index de49ce3..0000000 --- a/CONTRIBUTING.md +++ /dev/null @@ -1,116 +0,0 @@ -# Contributing to CVE Search API - -Thank you for considering contributions to the CVE Search API and the CVE Project's Automation Working Group! - -The following is a set of guidelines for contributing. In general, use your best judgement, and feel free to propose changes to this document in a pull request. - -## Table of Contents - -- [Code of Conduct](#code-of-conduct) -- [I just have a question](#i-just-have-a-question) -- [How Can I Contribute?](#how-can-i-contribute) - - [Reporting Bugs](#reporting-bugs) - - [Code Proposals](#code-proposals) - - [Pull Requests](#pull-requests) -- [Style Guides](#style-guides) - - [Git Commit Messages](#git-commit-messages) - - [JavaScript Style Guide](#javascript-style-guide) - -## Code of Conduct - -Contributors to this project are governed by the [Code of Conduct](CODE_OF_CONDUCT.md). By participating, you are expected to uphold this code. Please report unacceptable behavior via email to the AWG Chair at rbritton@mitre.org. - -## I just have a question - -Start with the [README](README.md) and its [API documentation guidance](README.md#swagger-api-docs). For other questions or help finding the appropriate community discussion channel, email the AWG Chair at rbritton@mitre.org. - -## How Can I Contribute? - -### Reporting Bugs - -This section guides you through submitting a bug report. Following these guidelines helps maintainers and the community understand your report, reproduce the behavior, and find related reports. - -Before creating bug reports, please check [existing reports](#before-submitting-a-bug-report). When creating a report, please [include the details below](#how-do-i-submit-a-good-bug-report) to help us reproduce and resolve the issue. - -> [!WARNING] -> Do not report security vulnerabilities in public issues or pull requests. Follow the private reporting instructions in [SECURITY.md](SECURITY.md). - -> **Note:** -> If you find a **Closed** issue that seems like it is the same thing that you're experiencing, open a new issue and include a link to the original issue in the body of your new one. - -#### Before Submitting A Bug Report - -**Search the [open issues](https://github.com/CVEProject/CVE-Search-API/issues?q=is%3Aopen+is%3Aissue)** to see if the problem has already been reported. If it has **and the issue is still open**, add a comment to the existing issue instead of opening a new one. - -#### How Do I Submit A (Good) Bug Report? - -Bugs are tracked in the [CVE Search API issue tracker](https://github.com/CVEProject/CVE-Search-API/issues). Include the following information in your report. - -Explain the problem and include additional details to help maintainers reproduce the problem: - -- **Use a clear and descriptive title** for the issue to identify the problem. -- **Describe the exact steps that reproduce the problem**. Include how you started or accessed the API, the endpoint and HTTP method, and a minimal request body or curl command. Remove credentials, private deployment URLs, and other sensitive information before sharing examples or logs. -- **Provide specific examples to demonstrate the steps**. Include links to files or GitHub projects, or copy/pasteable snippets, which you use in those examples. If you're providing snippets in the issue, use [Markdown code blocks](https://help.github.com/articles/markdown-basics/#multiple-lines). -- **Describe the behavior you observed after following the steps** and point out what exactly is the problem with that behavior. -- **Explain which behavior you expected to see instead and why.** -- **If the problem wasn't triggered by a specific action**, describe what you were doing before the problem happened and share more information using the guidelines below. - -Provide more context by answering these questions: - -- **Can you reliably reproduce the issue?** If not, provide details about how often the problem happens and under which conditions it normally happens. - -Include details about your configuration and environment: - -- **Which version of the API are you using?** -- **What's the name and version of the OS you're using**? -- **Are you running with npm or Docker, and which Node.js and OpenSearch versions are involved?** -- **Does the index contain the CVE Records and fields needed to reproduce the issue?** An incomplete local index can produce different results from a fully populated deployment. - -### Code Proposals - -This section guides you through submitting a code proposal for the CVE Search API, including completely new features and minor improvements to existing functionality. Following these guidelines helps maintainers and the community understand your proposal and find related suggestions. - -Before creating a code proposal, please check the [open issues](https://github.com/CVEProject/CVE-Search-API/issues?q=is%3Aopen+is%3Aissue) for related suggestions. Describe the use case and the steps you would take if the proposed feature existed, using the guidance below. - -#### How Do I Submit A (Good) Code Proposal? - -Enhancement suggestions are tracked in the [CVE Search API issue tracker](https://github.com/CVEProject/CVE-Search-API/issues). Please make sure to provide the following information: - -- **Use a clear and descriptive title** for the issue to identify the suggestion. -- **Provide a step-by-step description of the suggested enhancement** in as many details as possible. -- **Provide specific examples to demonstrate the steps when applicable**. Include copy/paste-able snippets which you use in those examples, as [Markdown code blocks](https://help.github.com/articles/markdown-basics/#multiple-lines). -- **Describe the current behavior** and **explain which behavior you expected to see instead** and why (if applicable). -- **Explain why this enhancement would be useful** to most users and isn't something that can or should be implemented as an outside service that just integrates with the API. - -### Pull Requests - -The process described here has several goals: - -- Maintain quality -- Fix problems that are important to users -- Engage the community in working toward the best possible solutions -- Enable a sustainable system for maintainers to review contributions - -Please follow these steps to have your contribution considered by the maintainers: - -1. Follow the instructions in [the template](PULL_REQUEST_TEMPLATE.md) -2. Follow the [style guides](#style-guides) -3. After you submit a pull request, verify that all [status checks](https://help.github.com/articles/about-status-checks/) pass
What if the status checks fail?If a status check fails and you believe that the failure is unrelated to your change, please leave a comment explaining why. If the failure was a false positive, a reviewer will open an issue to track that problem with the status check suite.
- -> **Note** -> A reviewer may ask you to complete additional design work, tests, or other changes before your pull request is accepted. - -## Style Guides - -### Git Commit Messages - -- Begin the message with the issue number, for example: "#123 this is the commit message". (Git CLI users should specify the message as a flag: `git commit -m "#123 message"` or change the [core.commentchar](https://git-scm.com/docs/git-config#Documentation/git-config.txt-corecommentChar) value.) -- Use the present tense ("Add feature" not "Added feature") -- Use the imperative mood ("Add filter..." not "Adds filter...") -- Limit the first line to 72 characters or less - -### JavaScript Style Guide - -Follow the repository's [ESLint configuration](eslint.config.js) and [Prettier configuration](.prettierrc.json), and prefer existing code patterns. Use `npm run lint` and `npm run format:check` to check style; `npm run lint:fix` and `npm run format` apply fixes. Review their changes before committing. - -The combined `npm run quality` command runs linting, formatting checks, and the Jest suite with coverage thresholds. See the [README testing section](README.md#testing) for the available checks. diff --git a/PULL_REQUEST_TEMPLATE.md b/PULL_REQUEST_TEMPLATE.md deleted file mode 100644 index 5c1445f..0000000 --- a/PULL_REQUEST_TEMPLATE.md +++ /dev/null @@ -1,25 +0,0 @@ -Note: Please format the pull request title like: -"Resolves issue ###, High level description of pull request." - -Closes Issue ### - -# Summary - -Write out a concise summary of this PR and its impact on the CVE Search API. - -# Important Changes - -`example_file.js` - -- Cleaned code and added comments. -- Added method to handle adding items. - -# Testing - -Steps to manually test updated functionality, if possible - -- [ ] 1) Example test step. - -# Notes - -- Some additional notes about this PR. diff --git a/README.md b/README.md index 6854015..fd53f3c 100644 --- a/README.md +++ b/README.md @@ -3,10 +3,7 @@ ## Table of Contents - [The CVE Search API Project](#the-cve-search-api-project) - - [OSS Contributor](#oss-contributor) - - [Working Groups](#working-groups) - - [Security](#security) - - [Reporting a Vulnerability](#reporting-a-vulnerability) + - [License](#license) - [Running the API locally](#running-the-api-locally) - [Docker API Only](#docker-api-only) - [Deploying with npm](#deploying-with-npm) @@ -26,26 +23,9 @@ This repository provides an API for searching CVE Records in an existing OpenSearch index. It supports the [CVE Program's mission](https://www.cve.org/About/Overview) to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities by making CVE Records searchable through structured filters and a raw-query endpoint. -There are several ways to contribute to the project and the wider CVE community. +### License -### OSS Contributor - -Developers can contribute code, documentation, bug reports, and improvement proposals. Start by reviewing the [open issues](https://github.com/CVEProject/CVE-Search-API/issues?q=is%3Aissue+is%3Aopen), then read the [contribution guide](CONTRIBUTING.md) and [pull request template](PULL_REQUEST_TEMPLATE.md). We welcome contributions that improve the CVE Search API. - -All participants are expected to follow the [Code of Conduct](CODE_OF_CONDUCT.md). The project's license is [CC0 1.0 Universal](LICENSE). - -### Working Groups - -The CVE Program operates focused working groups. Visit the [working groups page](https://www.cve.org/ProgramOrganization/WorkingGroups) to learn how to participate in the broader program. - -### Security - -#### Reporting a Vulnerability - -> [!WARNING] -> Do not put vulnerability information in a public GitHub issue or pull request. - -Follow the [security policy](SECURITY.md) for instructions on privately reporting a vulnerability in the CVE Search API. +The project's license is [CC0 1.0 Universal](LICENSE). ## Running the API locally diff --git a/SECURITY.md b/SECURITY.md deleted file mode 100644 index 4400c5d..0000000 --- a/SECURITY.md +++ /dev/null @@ -1,39 +0,0 @@ -# Security Policy - -- [Reporting a Vulnerability](#reporting-a-vulnerability) -- [Scope](#scope) -- [Fixes](#fixes) -- [Coordination](#coordination) - -## Reporting a Vulnerability - -Do not disclose vulnerability details in a public GitHub issue or pull request. - -Please report security vulnerabilities by going to the [CVE Program web forms](https://cveform.mitre.org/). Please include vulnerability details, steps to reproduce (e.g., proof-of-concept code, screenshots) and an assessment of the impact in your report. We appreciate concise and high quality reports. - -#### Web Form Guide - -- In the “Select a request type” drop down menu, please select “other” -- Enter your email address in the space provided -- You may enter a PGP key if you prefer to encrypt your correspondence -- In the “Type of comment” drop down menu, please select “Issue” -- In the textbox labeled “Please provide your question, issue, comment, etc.” please start the message with the following information: - - First Line: “CVE Search API Security Anomaly Report” - - Second Line: “Distribution: CVE Search API Development Team” - - Third Line: "Description: [Free Text description of the anomaly]” -- Enter the Security code -- Click “Submit Request” - -## Scope - -The API in the [CVE Search API repository](https://github.com/CVEProject/CVE-Search-API) is in scope for reporting vulnerabilities. - -## Fixes - -We will release fixes and assign CVE IDs for verified security vulnerabilities. We expect to publish vulnerabilities using GitHub [security advisories](https://github.com/CVEProject/CVE-Search-API/security/advisories). - -## Coordination - -We appreciate the opportunity to investigate and develop fixes before public disclosure, following coordinated vulnerability disclosure practices. - -For vulnerabilities that affect upstream dependencies, we can assist reporting and coordinating with the appropriate parties. We will not share your identification without your permission, but may share the other relevant parts of your report.