Data API

Changelog and versioning

What changed in the Data API, and how we change it without breaking your integration.

Version lifecycle policy

Current version
v1 Stable
Base URL
https://api.cybersecuritynews.us/v1
  • v1 is stable. We will not remove or rename fields, change their meaning or type, or remove endpoints or parameters in v1.
  • Additive changes ship in place. New endpoints, optional parameters, response fields and enum values (such as new event types) are added to v1 without notice beyond this changelog. Build clients that ignore fields and values they do not recognise.
  • Breaking changes only in a new major version (for example /v2), never in place.
  • At least 12 months of overlap. When a new major version ships, the previous one keeps working, unchanged, for at least 12 months.
  • Deprecation notices. Responses from a deprecated version carry a Deprecation header and a Sunset header with the shutdown date, and every account owner is emailed when the deprecation is announced and again before the sunset date.

Changes

  1. v1 Added

    Added /cves alias, severity & patched filters, patch fields, /threats, patch-released events

    • GET /v1/cves and GET /v1/cves/{id}: aliases of /v1/vulnerabilities, returning identical data.
    • severity filter (comma list of critical, high, medium, low; CVSS bands) and patched=true|false on the vulnerability list.
    • Vulnerabilities gained severity, patchAvailable and patchUrls. On the single-vulnerability response, each products[] entry now carries affectedVersions, fixedVersions and basis (kev, nvd or editor).
    • GET /v1/threats?vendor=&days=14: threat status, actively exploited CVEs, active incidents and recent events in one call (window 1 to 90 days).
    • New intelligence event type patch-released in /v1/intelligence.
  2. v1 Launch

    v1 launched

    • GET /v1/status: account, plan, limits and usage for the calling key.
    • GET /v1/news and GET /v1/news/{slug}: published stories with sources, updates and events.
    • GET /v1/vulnerabilities and GET /v1/vulnerabilities/{id}: CVEs with CVSS, exploitation, KEV listing, affected products and event history.
    • GET /v1/kev: the CISA Known Exploited Vulnerabilities catalog.
    • GET /v1/incidents: developing incidents and their status.
    • GET /v1/vendors, GET /v1/vendors/{slug} and GET /v1/products: the vendor and product catalog.
    • GET /v1/intelligence: the append-only intelligence event feed with cursor paging.
    • GET /v1/threat-status: the Cyber Threat Status and its evidence.
    • API keys with rotation and revocation, daily quotas, per-minute rate limits and a free 30-day trial with no card.