aboutcode-org / aboutcode-org/vulnerablecode

Collect (or re-collect) openSUSE and SUSE

未關閉
#84 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Data collection sys
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

We should revisit SUSE and OpenSUSE data.

1. there are new feeds at https://www.suse.com/support/security/
2. in particular there are now possibly overlapping CVRF, CSAF, VEX, and OSV formats at https://ftp.suse.com/pub/projects/security/ as well as scores in YAML format. These files and dirs are of interest:
```
csaf/ 16-Nov-2024 10:39 -
csaf-vex/ 16-Nov-2024 05:10 -
cvrf/ 17-Nov-2024 10:30 -
cvrf-cve/ 17-Nov-2024 03:41 -
cvrf1.2/ 17-Nov-2024 10:30 -
osv/ 16-Nov-2024 12:42 -
oval/ 17-Nov-2024 05:32 -
yaml/ 17-Nov-2024 09:31 -
csaf-vex.tar.bz2 16-Nov-2024 05:04 154M
csaf.tar.bz2 16-Nov-2024 11:06 76M
cvrf-cve.tar.bz2 01-Nov-2024 03:45 137M
cvrf.tar.bz2 16-Nov-2024 08:10 115M
cvrf1.2.tar.bz2 16-Nov-2024 09:05 117M
osv.tar.bz2 16-Nov-2024 12:43 15M
package2cpe.csv
```

4. distro downloads come with SBOMs like at https://updates.suse.com/SUSE/Products/SL-Micro/6.0/x86_64/iso/SL-Micro-6.0-Packages-x86_64-GM.cdx.json and https://www.suse.com/download/sle-micro/ both in SPDX and CycloneDX format
5. There is also a list at `opensuse-security@opensuse.org`:
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/
When looking at https://www.suse.com/security/cve/CVE-2019-14822/ it is not entirely clear how this intersects with SUSE proper:

6. See also #62

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。