You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When comparing results of vulndb and grype, turns out that often grype outputs GHSA while the whole idea of vulndb is to output CVEs.
So, for debug and research there is a need to output also the aliases field from osv to the cycloneDX we produce with the vulnerabilities.
Seems that the right place to document these aliases is in the cycloneDX->vulnerabilities[_]->references field, see here
The text was updated successfully, but these errors were encountered:
When comparing results of vulndb and grype, turns out that often grype outputs GHSA while the whole idea of vulndb is to output CVEs.
So, for debug and research there is a need to output also the aliases field from osv to the cycloneDX we produce with the vulnerabilities.
Seems that the right place to document these aliases is in the cycloneDX->vulnerabilities[_]->references field, see here
The text was updated successfully, but these errors were encountered: