Open-source package vulnerabilities
OSV.dev (CC-BY-4.0, 8 mainstream ecosystems) + GitHub’s github-reviewed advisories (CC-BY-4.0). Ingested independently — when the same vulnerability appears in both, both records are kept and flagged “also in” rather than silently merged.