-
Notifications
You must be signed in to change notification settings - Fork 190
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support RedHat vulnerabilities #1404
Comments
Hi, is adding RedHat datasource on your roadmap? |
This issue has not had any activity for 60 days and will be automatically closed in two weeks |
We're largely dependent on Red Hat to provide the data in the OSV format, conversations are ongoing... /cc @mprpic |
The Red Hat ecosystem is large and varied so we're still working out the kinks on how to best structure the data in the OSV schema, but it's in progress! Since there is interest in this data, I'll ask here @fingeromer, are you mostly interested in data on vulnerabilities affecting RPMs shipped on RHEL? Or other Red Hat products as well? |
The onboarding process is a little bit bespoke and toilsome at the moment, but something we're continuously improving on and streamlining with each new data source onboarded. I would like to get it to the point of being much more checklist/cookbook driven than it currently is. My detailed response here is an (ongoing) experiment at further process improvement and seeks to address some recent actionable feedback received by another data source onboarding. Your actionable feedback is also very welcome. In a nutshell:
Known onboarding rough edges:
|
We going to publish the records at a new REST endpoint |
I guess we don't need to adjust purl_helpers because we include purls with our OSV records. |
Correct. |
Reserved an ecosystem prefix Red Hat |
Add the `Red Hat` ecosystem, see google/osv.dev#1404 --------- Signed-off-by: Jason Shepherd <jshepher@redhat.com> Signed-off-by: Andrew Pollock <andrewpollock@users.noreply.github.com> Co-authored-by: Andrew Pollock <andrewpollock@users.noreply.github.com>
Testing of Red Hat RPM security data. See #1404
Now available: https://openssf.org/blog/2024/11/01/red-hats-collaboration-with-the-openssf-and-osv-dev-yields-results-red-hat-security-data-now-available-in-the-osv-format/. I think this issue can be closed now :-) |
Currently OSV supports a few operating system ecosystems like Debian & Alpine.
We would like to open a feature request for supporting RedHat ecosystem vulnerabilities.
Thanks, have a nice day.
The text was updated successfully, but these errors were encountered: