Standard workflow
Use the standard workflow to retrieve CVE patch data, retrieve patch files, and generate a Fixlet.
Procedure
-
Retrieve CVE patch data.
Example request:
{ "cve_id": "CVE-2025-21179" }Review the returned KB articles, products, CPE data, patch availability, and any selection warning. Do not continue until the intended product is unambiguous. -
Retrieve patch files.
Microsoft example:
{ "vendor": "microsoft", "kb_article_id": "5051987", "architecture": "x64" }WinGet example:
{ "vendor": "winget", "package_id": "Mozilla.Firefox", "version": "145.0", "architecture": "x64" }Review every filename, URL, size, hash, and verification warning. Vendor metadata is an input to generation, not deployment approval. -
Generate the Fixlet.
Pass the selected product and patch files to
generate_fixlet. A simplified Microsoft example is:{ "cve_id": "CVE-2025-21179", "kb_article_id": "5051987", "product_name": "Windows 11 Version 24H2 for x64-based Systems", "severity": "Important", "files": [ { "filename": "windows11-kb5051987-x64.msu", "sha1": "<vendor-sha1>", "sha256": "<vendor-sha256>", "size_bytes": 123456, "download_url": "https://catalog.sf.dl.delivery.mp.microsoft.com/<path>" } ] }Use the exact metadata returned by the lookup tools. Do not substitute placeholder hashes or file sizes in production content.
Results
The generator accepts only HTTPS downloads from trusted vendor hosts. The release-shipped policy is embedded in the binary from config/trusted-download-hosts.json; it includes the Microsoft Update Catalog and Google Chrome hosts. Maintainers add broadly approved vendor hosts to that source-controlled file, keep entries lowercase and lexicographically sorted, review the change as security policy, and rebuild the binary.
WinGet installer hosts vary by publisher. An administrator can append deployment-specific exact hostnames at startup without changing the embedded policy:
export FIXLET_TRUSTED_DOWNLOAD_HOSTS="download.mozilla.org,downloads.vendor.example"
The setting is a comma-separated list of exact DNS hostnames. Wildcards, URL paths, IP
addresses, HTTP URLs, user information, and nonstandard ports are not accepted. A URL
supplied to generate_fixlet is rejected unless its normalized
hostname is in the embedded or administrator-configured allowlist. Invalid embedded
policy prevents server startup; invalid runtime entries are rejected during URL
validation.
What to do next
Review the generated content before you import or deploy it. For details, see Reviewing generated content.