Sources
The indicator corpus is built from public and openly licensed feeds, and the Sources page in the console names them. It lists every feed contributing today and every one that has passed review and is waiting on a collector, and it carries the notices those licences ask for. The CVE corpus is a separate matter, published by Wazuh CTI and described in The corpus.
Contributing and pending
The page has two lists. Contributing today is the feeds a lookup actually reads. Pending is the feeds that have passed the same licence review and are waiting on a collector to be written, listed so the roster is honest about what is and is not live rather than implying the corpus already draws on all of them. A feed moves from pending to contributing when its collector ships, with no change a reader has to make.
Feeds are fetched once a day. A source that fails on a given day is skipped for that day rather than being allowed to stop the others, so one feed being down never empties the corpus.
Commercial use and licences
Every source on the page permits commercial use, and none of them required a signed agreement to use. Where a licence asks for a notice to be preserved, the notice is shown on the source's entry, rendered exactly as the licence carries it. Several sources ask for nothing and say so.
Why a source is named here and nowhere else
The number of independent sources that corroborate an indicator is shown on the indicator, because that count is what its confidence rests on. The names of those sources are not. They live on this page, corpus-wide, and are never attached to a single indicator.
Two things follow from that. A source can be withdrawn from the corpus cleanly, because no record points back at it by name. And no single feed is exposed one indicator at a time, which is a condition several of the licences place on redistributing what they publish. A lookup therefore answers with what the corpus holds and how many sources back it, and this page answers who those sources are in general.