vmware / vmware/photon

https://packages.broadcom.com/photon/photon_cve_metadata schema was changed

Open
#1,638 7 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
C
Stars
3.2k
Forks
692
PR merge metrics
No merged PRs in 30d

Description

Describe the bug

Hello!

We use advisories from https://packages.broadcom.com/photon/photon_cve_metadata/cve_data_photon<ver>.json (where ver we take from the photon_versions.json file).
Yesterday changes occurred in the repository:

  • The photon_versions.json file was deleted.
  • Instead of a file with advisories for a specific release (for example, cve_data_photon5.0.json), there's a cve folder. The information in these advisories doesn't include:
    • release number
    • cve_score

Are these expected changes?
If yes, are you planning to somehow enrich these advisories with the data that was "lost"?
Or perhaps you have another source to get CVE lists in machine-readable format.

Thanks in advance for your response!
Regards, Dmitriy

Reproduction steps
  1. Check photon_versions.json and cve_data_photon<ver>.json files in https://packages.broadcom.com/photon/photon_cve_metadata.
Expected behavior

The existence of photon_versions.json and cve_data_photon<ver>.json files

Additional context

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Compare photon_versions.json and the cve_data_photon.json files referenced in the issue with the current cve folder contents at the packages.broadcom.com URL. Determine whether the changed schema is intentional and whether release numbers, CVE scores, or an alternative machine-readable source are available; done means a maintainer-confirmed source and migration guidance.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.