Skip to content

Question: procedure for moving from package-wise to CVE-wise advisories #6005

Description

Hi

We currently publish advisories grouped by package release: one advisory per package version, listing all the CVEs fixed in that release. We're considering restructuring this so each advisory is grouped by CVE instead (one advisory per CVE, with an affected entry for each package it touches).

Before we make this change, we wanted to check with you on two things:

  1. Procedure: Is there a defined process for changing how we structure/group our advisories, or would this require any changes on OSV's end to support? If a compatible structure or set of conventions already exists for CVE-grouped advisories, we'd appreciate a pointer to it.

  2. Handling existing records: Since this change restructures how we group vulnerabilities rather than deleting or altering existing advisory content, how should we handle the transition on OSV.dev's side? Specifically, how does OSV.dev expect us to manage the relationship between old package-wise advisory IDs and new CVE-wise ones (e.g. via related, withdrawn, or another mechanism), so that deduplication and matching continue to work correctly?

Any guidance here would be really helpful before we start migrating.

Thanks!

--------- Related Labels ------------

  • enhancement
  • data quality

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions