-
Notifications
You must be signed in to change notification settings - Fork 5
Open
Labels
lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.Denotes an issue or PR that has aged beyond stale and will be auto-closed.
Description
It would be great to keep this CVE feed current and updated.
I discovered its existence in this discussion:
@andrewpollock (who contributes to OSV) wrote in aboutcode-org/vulnerablecode#1661 (comment)
I did a quick Google search and happened upon https://github.com/kubernetes-sigs/cve-feed-osv (which makes me wonder why we haven't got OSV.dev importing it, but it is the first I knew of it) @oliverchang FYI
But the repo is not in sync with the latest security feed.
For instance, as of today:
- https://github.com/kubernetes-sigs/cve-feed-osv/tree/bba03244f6bf56a813d5ab918d0d5c78d260d15e/vulns is missing two CVEs reported in https://groups.google.com/g/kubernetes-announce/c/ufYd_aq4Y20/m/V3LKIffxCAAJ CVE-2024-9486 and CVE-2024-9594
Questions:
- What is the process and which tools do you use to keep this current?
- How can we help?
Metadata
Metadata
Assignees
Labels
lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.Denotes an issue or PR that has aged beyond stale and will be auto-closed.