rdmbair15m5-changelog-20260901-0525-build-cvedb-app-nvd-cache-mcp-service
rdmbair15m5-changelog-20260901-0525-build-cvedb-app-nvd-cache-mcp-service
Built and verified cveDB.app (cvedb), a
high-performance local caching daemon, CLI tool, Model Context Protocol
(MCP) server, and HTTP/SSE service for NVD/CVE records with zstandard
payload compression, housekeeping retention policies, and multi-persona
security evaluations.
Scope & Inventory
- Hosts Touched:
rdmbair15m5(local work),rdmsm4x(canonical hub). - Target Directories:
rdmsm4x:~/dev/apps/cvedb/&rdmsm4x:~/dev/apps/cveDB/rdmbair15m5:~/dev/apps/cvedb/&rdmbair15m5:~/dev/apps/cveDB/
- Fleet Ticketing: Registered
FEAT-20260901-02inissueRoo(/Users/richh/dev/issues/open/FEAT-20260901-02-*.md). - Registries Updated:
/Users/richh/dev/apps/PORTFOLIO_PRD.md~/.agent-coordination/PROJECTS.md
Key Architecture & Features Built
- Multi-Source Ingestion Engine
(
pkg/ingest/):- Cold-start bootstrap importer (
cvedbio.go) for.json,.jsonl/NDJSON, and.gzarchive datasets. - NIST NVD API v2.0 client (
nvd.go) withNVD_API_KEYauthentication, dynamic rate limiting (0.6s with key, 6.0s without), exponential backoff/jitter, prioritized recent CVE sync, and 120-day chunked reverse-chronological backfill. - CISA Known Exploited Vulnerabilities (KEV) catalog synchronization
(
kev.go) with automatedis_protected = 1pruning immunity. - FIRST.org EPSS exploit prediction scoring synchronization
(
epss.go). - Resilient background daemon runner (
daemon.go) with scheduled intervals, macOS notifications, and SSE dispatch.
- Cold-start bootstrap importer (
- Storage & Compression Engine (
pkg/storage/,pkg/compression/):- SQLite embedded database with WAL mode, FTS5 full-text indexing, and remote volume mount support.
- Zstandard (zstd) payload compression delivering >50% space savings with >100 MB/s decompression throughput.
- Live compression benchmark command
(
cvedb bench-compression).
- Housekeeping & Selective Pruning Engine
(
pkg/housekeeping/):- Configurable storage capacity thresholds
(
--max-size). - Selective retention matrix: Protects all CISA KEV entries, high CVSS
records (>= 8.0), watched vendor CPEs (Apple, Google, Microsoft,
Linux, Cisco, OpenSSL), and recent CVEs while selectively pruning
low-severity aged records with automatic
VACUUMcompaction.
- Configurable storage capacity thresholds
(
- Developer Interfaces (
pkg/tui/,pkg/mcp/,pkg/api/,pkg/notify/):- CLI Query tool (
cvedb query) with sub-millisecond filtering and JSON/NDJSON export. - Interactive terminal record browser (
cvedb browse) with ANSI color-coded CVSS vectors and paginated search. - stdio Model Context Protocol (MCP) server (
cvedb mcp) implementingget_cve,search_cves,get_recent_cves,check_kev,get_stats,suggest_remediation, andmatch_cpe. - Local HTTP REST API & Server-Sent Events (SSE) server
(
/api/v1/events/stream). - Native macOS User Notifications via Notification Center.
- CLI Query tool (
- Multi-Persona Security Evaluation
(
SECURITY_PERSONA_EVALUATION.md):- Evaluated across Threat Hunter, Security Tool Builder, Vulnerability Researcher, and Red Team Hacker personas with integrated feature contributions (IOC extraction, MITRE ATT&CK mapping, PoC harvester, local CPE matcher).
Verification Evidence
- Build & Version: Executed
cvedb versionproducingcveDB.app v0.1.0 (East Coast Science, LLC). - Unit & Feature Test Suites:
go test -v ./...passed 100% across all packages (pkg/api,pkg/compression,pkg/mcp,pkg/persona,pkg/storage,test/e2e). - Remote Host Verification: Synchronized to
rdmsm4x:~/dev/apps/cvedband compiled/tested cleanly via SSH. - Ticket Activity: Updated
FEAT-20260901-02with completion comments and test evidence.