ThreatWatch Feed Freshness
A reachable feed can still be stale. I made freshness visible so old data no longer looked current.
Freshness scoring
I added a check for whether each ThreatWatch source was updating within its expected cadence. A source can be technically reachable while still serving old data, so basic uptime is not enough.
Freshness now contributes to source health alongside collection success and evidence quality. This makes the briefing more transparent and helps prevent old reporting from being presented as a current development.
What changed for me
Data quality needs to be visible at the point of use. Analysts should be able to distinguish fresh reporting, historical context, and unavailable sources without inspecting pipeline logs.
The same principle will carry into RedBlue: any operational recommendation should expose the age and origin of the evidence behind it.