bom-squad / vulndb

Ingesting and modeling tools for NVD (Vulnerabilities and Products) and OSV
Apache License 2.0
1 stars 3 forks source link

Output aliases #13

Open dn-scribe opened 10 months ago

dn-scribe commented 10 months ago

When comparing results of vulndb and grype, turns out that often grype outputs GHSA while the whole idea of vulndb is to output CVEs. So, for debug and research there is a need to output also the aliases field from osv to the cycloneDX we produce with the vulnerabilities.

Seems that the right place to document these aliases is in the cycloneDX->vulnerabilities[_]->references field, see here