Only sync CVE records published on or after this time. Omit to sync the full NVD
history, which is around 389,000 CVE records and takes about an hour on the first
sync. Every sync after that is incremental and takes seconds.
Note that this filters on the publication date of the CVE record, not on when NVD last changed it,
so a CVE published before start_date is never synced even if its CVSS score was
updated yesterday. Leave start_date unset when the table is used to look up scores
for arbitrary CVE IDs, such as those found in aws_ssm_instance_patches.cve_ids.
Changing this value resets the incremental cursor and triggers a fresh backfill.