Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support Ubuntu vulnerabilities #1511

Closed
fingeromer opened this issue Jul 30, 2023 · 2 comments
Closed

Support Ubuntu vulnerabilities #1511

fingeromer opened this issue Jul 30, 2023 · 2 comments

Comments

@fingeromer
Copy link

fingeromer commented Jul 30, 2023

Ubuntu is basically Debian, but it seems like when requesting vulnerabilities with Ubuntu's purl (pkg:deb/ubuntu*) , nothing returns.

@andrewpollock
Copy link
Contributor

Ubuntu is basically Debian

For the purposes of this conversation, only if you squint really really hard :-)

We're converting Debian security advisories to OSV ourselves with https://github.com/ossf/osv-schema/tree/main/tools/debian

We'll need to do something similar (but different) to achieve the same with Ubuntu. I briefly took a look at how Ubuntu rolls, and while also thinking about #1404 and I'm wondering if doing something with both OVAL feeds would be possible (and somewhat reusable).

It's something we'll have to explore further. Given you filed this and #1404 would you be interested in collaborating with us on this?

@oliverchang
Copy link
Collaborator

See #1113 for the data source addition status for Ubuntu.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants