aboutcode-org / vulnerablecode

A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
https://public.vulnerablecode.io
Apache License 2.0
520 stars 190 forks source link

Collect rockylinux advisories #753

Open pombredanne opened 2 years ago

pombredanne commented 2 years ago

This is a RH derivative (following CentOS changes) see https://rockylinux.org https://errata.rockylinux.org/ has the list ... same look as Alma linux #750 but different API https://errata.rockylinux.org/api/advisories and https://errata.rockylinux.org/api/advisories/RLSA-2022:2199

TG1999 commented 1 year ago

Use this API endpoint instead https://errata.rockylinux.org/api/v2/advisories?filters.product=&filters.fetchRelated=false&page=0&limit=25

pombredanne commented 1 month ago

From today's call: https://errata.rockylinux.org/api/v2/advisories?filters.product=&filters.fetchRelated=true (then paginate &page=0&limit=25)

pombredanne commented 1 month ago

@ambuj-1211 FYI

pombredanne commented 1 month ago

See:

pombredanne commented 1 month ago

(I likely filed the peridot issue in the wrong repo) .... Should be in https://github.com/resf/distro-tools/tree/main/apollo instead

AyanSinhaMahapatra commented 1 month ago

Btw, from above ^

Hey - No worries about filing it here. The license for the errata data is the same as RH, that is, CC-BY-4.0.

The data resources linked on this page as well as their alternative representations available through the Security Data API are licensed under the Creative Commons Attribution 4.0 International License. If you distribute this content or a modified version of it, you must provide attribution to Red Hat, Inc. and provide a link to the original.

https://access.redhat.com/security/data

pombredanne commented 1 month ago

Per https://github.com/rocky-linux/peridot/issues/191#issuecomment-2248933377

Hey - No worries about filing it here. The license for the errata data is the same as RH, that is, CC-BY-4.0.

The data resources linked on this page as well as their alternative representations available through the Security Data API are licensed under the Creative Commons Attribution 4.0 International License. If you distribute this content or a modified version of it, you must provide attribution to Red Hat, Inc. and provide a link to the original.

https://access.redhat.com/security/data