[cveMetadata](https://cveproject.github.io/cve-schema/schema/docs/#oneOf_i0_cveMetadata) should require datePublished and datePublic. In practice these are enforced by CVE Services, with possible exception for the Secretariat "client zero."