v2.5.2
v2.5.2
Two changes, one patch — both from Forward design-partner follow-ups. NQE stays the source of truth: the Python adapters only resolve foreign keys; every guard/clamp/severity-map lives in the query.
Feature — optional netbox-dlm CVE + Vulnerability feed
Two new opt-in NQE maps (disabled by default) import Forward's security analysis into the netbox-dlm plugin:
netbox_dlm.cve←network.cveDatabase.cves— global CVE catalog; worst-case per-vendor severity →CVESeverityChoices(usesVendorCveInfo, not the deprecatedCve.severity/description).netbox_dlm.vulnerability←device.cveFindingswhereisVulnerable— one row per device↔CVE.
FK safety is belt-and-suspenders: in-query isPresent(osVersion) gate + adapter ensure_dlm_cve/ensure_dlm_software_version create-if-missing (empty update_values never clobber the catalog/versions row). Apply order cve+softwareversion before vulnerability; delete order reversed. Live-verified: 5,038 CVEs, 73,973 vulnerabilities / 4,728 devices, 0 dangling FKs.
Requires the netbox-dlm plugin. netbox-dlm 0.2.0+ ships migrations — run migrate; 0.1.0 needs makemigrations netbox_dlm first. The Vulnerability map is large (~16 rows/device) — enable it scoped or on a fresh branch first.
Fix — SNMP endpoint platform unification
Avocent devices fragmented across Avocent (enterprise OID 10418), AlterPath (legacy Cyclades OID 2925), and SNMP (empty sysDescr). The endpoint branch now folds Avocent/Cyclades/AlterPath into one Avocent platform, whitespace-collapses multiline sysDescr, and falls back to Unknown instead of a fake SNMP vendor.
Query-only endpoint change — run Publish Bundled Queries + Refresh Query IDs after upgrading.