Skip to content

feat: Adding alternative vulnerability data sources #4100

@anthonyharrison

Description

@anthonyharrison

Description

There are now multiple data sources of vulnerabilities which can be used to assess components. Supporting more may provide more accurate reporting of vulnerabilities.

Why?

With the issues which the NVD is experiencing alternative sources of vulnerability information are now being used across industry.

Suggest supporting the data from CVE.org which contains CVE records in JSON format and includes additional information such as CVSS V4 scores and PURL records (will be supported from schema version 5.1).

Anything else?

Other potential sources to consider are:

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions