envoyproxy / envoyproxy/envoy

CVE scanner depends on deprecated CVE data feeds

Open
#25,680 3 comments 0 reactions 1 assignee Claimed by @phlax View on GitHub
bug dependencies deprecation no stalebot
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 20h
Merged PRs (30d)
428

Description

Currently we download the vulnerability data feeds from NIST

These data feeds are set to be removed in september 2023 (https://nvd.nist.gov/vuln/data-feeds)

The suggested fix is to move to querying APIs

The current way is v expensive resource-wise so moving to APIs is a good idea anyway, but looks like this now has some urgency

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.