aquasecurity / vuln-list-update

Apache License 2.0
175 stars 99 forks source link

migrate SUSE to csaf-vex data source #304

Open dirkmueller opened 2 months ago

dirkmueller commented 2 months ago

SUSE started publishing vulnerability information in VEX format which as some more details. please consider leveraging that data source in addition or instead of the currently consumed csrf data.

https://ftp.suse.com/pub/projects/security/csaf-vex/

knqyf263 commented 2 months ago

We'll work on https://github.com/aquasecurity/trivy/issues/7452 this month. It would be great if someone could help us migrate SUSE.

dirkmueller commented 2 months ago

sure, happy to help when there is a draft patch for RH, it should be similar for SUSE then