Skip to content

Conversation

jess-lowe
Copy link
Contributor

@jess-lowe jess-lowe commented Sep 3, 2025

Starting to deal with #2465

Closes #3899

Copy link
Contributor

@another-rex another-rex left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two options here for the modified and published date.

  1. Keep the existing architecture of outputting stuff to combine-to-osv, and just have that emit two records, DEBIAN-CVE and CVE-

  2. Download the CVEs here as well (I think we mirror them to our own bucket already right? At least the NVD entries, so we can just download from that), and map them here.

I think option 2 is probably better here.

Copy link
Contributor

@another-rex another-rex left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking good, added some more comments!

another-rex
another-rex previously approved these changes Sep 10, 2025
Copy link
Contributor

@another-rex another-rex left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@jess-lowe jess-lowe merged commit 2c251e0 into google:master Sep 16, 2025
17 checks passed
jess-lowe added a commit that referenced this pull request Sep 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Decouple Debian reports from main CVE report
2 participants