The CVE plugin pulls the NVD National Vulnerability Database feed
and projects each entry as a cve.vulnerability resource so checks
can join sensor-inventoried packages against published CVEs in a
single query.
- Catalog-only. No customer credentials; the plugin reads the public NVD JSON feed.
- Reconciled hourly. A system-scheduled refresh keeps the local table fresh without manual operator action.
