When comparing results of vulndb and grype, turns out that often grype outputs GHSA while the whole idea of vulndb is to output CVEs.
So, for debug and research there is a need to output also the aliases field from osv to the cycloneDX we produce with the vulnerabilities.
Seems that the right place to document these aliases is in the cycloneDX->vulnerabilities[_]->references field, see here
When comparing results of vulndb and grype, turns out that often grype outputs GHSA while the whole idea of vulndb is to output CVEs. So, for debug and research there is a need to output also the aliases field from osv to the cycloneDX we produce with the vulnerabilities.
Seems that the right place to document these aliases is in the cycloneDX->vulnerabilities[_]->references field, see here