Skip to content

Commit 988c5e9

Browse files
authored
Merge pull request #89 from TG1999/add-vcio-migration-announcement-aboutcode
Add VCIO migration announcement blog post
2 parents 0aec8dd + 372f0ab commit 988c5e9

1 file changed

Lines changed: 51 additions & 0 deletions

File tree

Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
---
2+
slug: vcio-migration-announcement-aboutcode
3+
title: VulnerableCode API Deprecation and V3 Introduction
4+
authors: [tg1999]
5+
tags: [vcio, vulnerabilities, advisories, purl, api]
6+
hide_table_of_contents: false
7+
---
8+
9+
# VulnerableCode API Deprecation and V3 Introduction
10+
11+
The AboutCode team is planning to deprecate the V1 and V2 API of VulnerableCode (public.vulnerablecode.io) by the end of Q2 2026 (June 20, 2026). We are introducing V3 API and UI by the end of January 2026.
12+
13+
---
14+
15+
## Why this new API
16+
17+
The existing V1 and V2 APIs are both based on the “vulnerabilities” model, designed to aggregate information from multiple advisory sources based on identifiers and aliases. With the "vulnerabilities" model it is difficult to determine which source is correct because of the combination of sources. This may result in data from one source overwriting data from another source.
18+
19+
---
20+
21+
## What to expect from the new V3 API and UI
22+
23+
Moving forward, VulnerableCode will report “advisories” for packages and not “vulnerabilities”.
24+
25+
Currently if a package has 4 advisories and those 4 advisories were correlated with each other by their aliases and identifiers, we report a single vulnerability affecting that package. The new approach in V3 will report 4 individual advisories.
26+
27+
The new “advisories” model introduces an Advisory ID (AVID) for each advisory in VulnerableCode. An AVID will have different components like the source and the natural unique identifier used at that source. For example if we are importing an advisory from “nodejs_security_wg” and it’s identified by its ID “123”, the AVID will be “nodejs_security_wg/123”.
28+
29+
---
30+
31+
## Plan and Timeline
32+
33+
We are planning to complete the following tasks by the end of January 2026:
34+
35+
- Redesigning the API and UI
36+
- Migrating our existing data sources
37+
- Documenting the V3 API and the new UI
38+
39+
---
40+
41+
## Current Status
42+
43+
https://public2.vulnerablecode.io/v2 uses the new advisory based UI
44+
https://public2.vulnerablecode.io/api/v3/ uses new API, but it is still under development and not ready for production use.
45+
46+
---
47+
48+
## Migration Progress
49+
50+
You can track the progress of migration here:
51+
https://github.com/orgs/aboutcode-org/projects/52/views/48

0 commit comments

Comments
 (0)