anchore / nvd-data-overrides

Creative Commons Zero v1.0 Universal
44 stars 5 forks source link

Consider becoming an ADP rather than NVD alternative #13

Open prabhu opened 5 months ago

prabhu commented 5 months ago

CVE project supports enhancing the record as an Authorized Data Publisher (ADP). The benefit of this approach is that the enhancement data can be supplied in a consistent CVE 5.0 schema as adpContainer attributes. A given CVE 5.0 record could have multiple enhancements from multiple ADPs supporting workflows based on provider org id.

References

https://github.com/CVEProject/cve-schema/blob/master/schema/v5.0/CVE_JSON_5.0_schema.json#L591 https://www.cve.org/Media/News/item/podcast/2021/12/14/Enhancing-CVE-Records-as-an

joshbressers commented 5 months ago

I think we're too early to have this conversation. Perhaps someday. I'll leave this open so we don't forget.