kubernetes / kubernetes/sig-security

tooling: include `kubernetes-sigs/cve-feed-osv` OSV information in the CVE feed

Open
#178 6 comments 0 reactions 0 assignees View on GitHub
sig/security
Dominant language
Go
Stars
249
Forks
82
Avg merge
7d 12h
Merged PRs (30d)
2

Description

Sub-issue of https://github.com/kubernetes/sig-security/issues/177, see all the context and explanations there.

In short it consists of parsing the OSV content from https://github.com/kubernetes-sigs/cve-feed-osv/tree/main/vulns an including it in the JSON feed.

Contributor guide

Open the contributing guide

Research direction

Read the parent issue for the missing context, then inspect the OSV sources in kubernetes-sigs/cve-feed-osv/vulns and the repository's JSON feed entry point. Determine how the feed currently represents CVE data; done means OSV information is parsed and included in the generated JSON feed.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security, tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.