Hard Guard Vulnerability Intelligence — source notices
======================================================

This file documents the source/attribution hooks used by the 1.13.1 feed builder.
It is not legal advice. Review the current upstream terms before production publication.

CVE Program / CVE List V5
-------------------------
Source: https://github.com/CVEProject/cvelistV5
Terms: https://www.cve.org/legal/termsofuse

The builder requires --cve-license-file. Put the current MITRE copyright designation
and the CVE Usage license from the official Terms of Use in that operator-managed file.
The contents are embedded in the signed feed's legal_notices.cve field.

NIST National Vulnerability Database (optional enrichment)
-----------------------------------------------------------
Terms: https://nvd.nist.gov/developers/terms-of-use
Required application notice used by Hard Guard when NVD is present:
"This product uses data from the NVD API but is not endorsed or certified by the NVD."

Do not label modified/normalized Hard Guard data as if NVD authored the modifications.
The feed records NVD as an enrichment source only where NVD data was actually used.

GitHub Advisory Database (optional enrichment)
-----------------------------------------------
Source: https://github.com/github/advisory-database
License: CC BY 4.0
License URL: https://creativecommons.org/licenses/by/4.0/

CISA Known Exploited Vulnerabilities (optional enrichment)
-----------------------------------------------------------
Source: https://github.com/cisagov/kev-data
License: CC0 1.0 Universal
License URL: https://creativecommons.org/publicdomain/zero/1.0/
