/** * CVE Harvest Orchestrator — mines security advisories from the GitHub Advisory * Database to expand the Assay verification pattern library. * * Pipeline: discover advisories → fetch fix diffs → filter hunks → * generalize patterns → validate → catalog * * Each CVE fix commit represents a confirmed vulnerability with a confirmed fix. * The diff between vulnerable and patched code IS a verification pattern. * Signal density is near 100%: these are real bugs with real fixes. */ /** Track which advisories have been processed to allow resuming. */ export type CVEProgress = Record; export declare function loadCVEProgress(dir: string): Promise; export declare function saveCVEProgress(dir: string, progress: CVEProgress): Promise; export interface CVEHarvestConfig { /** Ecosystems to query. Defaults to ['npm']. */ ecosystems?: string[]; /** Minimum severity. Defaults to 'medium'. */ minSeverity?: 'critical' | 'high' | 'medium' | 'low'; /** Max advisories per ecosystem. */ maxPerEcosystem?: number; /** Only advisories published after this date. */ publishedAfter?: string; /** Harvest exactly these advisories by GHSA id (targeted mode — e.g. recall-benchmark misses). */ ghsaIds?: string[]; /** Stop after discovery and report what would be harvested, without LLM calls. */ dryRun?: boolean; /** Assay project root where rules go. */ catalogPath: string; /** Where cve-progress.json lives. */ progressDir: string; /** Where run reports go. */ runsDir: string; /** Model name for reporting. */ model: string; /** Skip already-processed advisories. */ resume?: boolean; /** * Held-out multi-file corpus dir (recall fix-pair cache) for the * corpus over-firing gate. Gate is skipped when unset or empty. */ corpusDir?: string; /** Override the corpus gate's per-file fire cap (default 20). */ corpusMaxFiresPerFile?: number; /** Override the corpus gate's noisy-file cap (default 2). */ corpusMaxNoisyFiles?: number; /** Logging callback. */ onLog?: (msg: string) => void; } export declare function harvestCVEs(config: CVEHarvestConfig): Promise;