{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "CyberLens Vulnerability Enrichment STIX Property Extension",
  "description": "Public distribution contract for governed vulnerability enrichment. It does not describe internal storage, ingestion, correlation, or scoring implementation.",
  "type": "object",
  "additionalProperties": false,
  "properties": {
    "extension_type": {"const": "property-extension"},
    "schema_version": {"const": "1.0.0"},
    "kev": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "authoritative_source": {"const": "CISA"},
        "is_kev": {"type": "boolean"},
        "date_added": {"type": "string"},
        "due_date": {"type": "string"},
        "required_action": {"type": "string"},
        "known_ransomware_campaign_use": {"type": "string"}
      },
      "required": ["authoritative_source"]
    },
    "epss": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "authoritative_source": {"const": "FIRST"},
        "score": {"type": "number"},
        "percentile": {"type": "number"},
        "score_date": {"type": "string"}
      },
      "required": ["authoritative_source"]
    },
    "risk": {
      "type": "object",
      "additionalProperties": false,
      "properties": {
        "producer": {"type": "string", "minLength": 1},
        "score": {"type": "number"},
        "level": {"type": "string"},
        "priority": {"type": ["string", "number", "integer", "boolean"]}
      },
      "required": ["producer"]
    }
  },
  "required": ["extension_type", "schema_version"]
}
