aboutcode-org / aboutcode-org/vulnerablecode

Collect (or re-collect) openSUSE and SUSE

未关闭
#84 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Data collection sys
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

We should revisit SUSE and OpenSUSE data.

1. there are new feeds at https://www.suse.com/support/security/
2. in particular there are now possibly overlapping CVRF, CSAF, VEX, and OSV formats at https://ftp.suse.com/pub/projects/security/ as well as scores in YAML format. These files and dirs are of interest:
```
csaf/ 16-Nov-2024 10:39 -
csaf-vex/ 16-Nov-2024 05:10 -
cvrf/ 17-Nov-2024 10:30 -
cvrf-cve/ 17-Nov-2024 03:41 -
cvrf1.2/ 17-Nov-2024 10:30 -
osv/ 16-Nov-2024 12:42 -
oval/ 17-Nov-2024 05:32 -
yaml/ 17-Nov-2024 09:31 -
csaf-vex.tar.bz2 16-Nov-2024 05:04 154M
csaf.tar.bz2 16-Nov-2024 11:06 76M
cvrf-cve.tar.bz2 01-Nov-2024 03:45 137M
cvrf.tar.bz2 16-Nov-2024 08:10 115M
cvrf1.2.tar.bz2 16-Nov-2024 09:05 117M
osv.tar.bz2 16-Nov-2024 12:43 15M
package2cpe.csv
```

4. distro downloads come with SBOMs like at https://updates.suse.com/SUSE/Products/SL-Micro/6.0/x86_64/iso/SL-Micro-6.0-Packages-x86_64-GM.cdx.json and https://www.suse.com/download/sle-micro/ both in SPDX and CycloneDX format
5. There is also a list at `opensuse-security@opensuse.org`:
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/
When looking at https://www.suse.com/security/cve/CVE-2019-14822/ it is not entirely clear how this intersects with SUSE proper:

6. See also #62

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。