Hi
We currently publish advisories grouped by package release: one advisory per package version, listing all the CVEs fixed in that release. We're considering restructuring this so each advisory is grouped by CVE instead (one advisory per CVE, with an affected entry for each package it touches).
Before we make this change, we wanted to check with you on two things:
-
Procedure: Is there a defined process for changing how we structure/group our advisories, or would this require any changes on OSV's end to support? If a compatible structure or set of conventions already exists for CVE-grouped advisories, we'd appreciate a pointer to it.
-
Handling existing records: Since this change restructures how we group vulnerabilities rather than deleting or altering existing advisory content, how should we handle the transition on OSV.dev's side? Specifically, how does OSV.dev expect us to manage the relationship between old package-wise advisory IDs and new CVE-wise ones (e.g. via related, withdrawn, or another mechanism), so that deduplication and matching continue to work correctly?
Any guidance here would be really helpful before we start migrating.
Thanks!
--------- Related Labels ------------
Hi
We currently publish advisories grouped by package release: one advisory per package version, listing all the CVEs fixed in that release. We're considering restructuring this so each advisory is grouped by CVE instead (one advisory per CVE, with an
affectedentry for each package it touches).Before we make this change, we wanted to check with you on two things:
Procedure: Is there a defined process for changing how we structure/group our advisories, or would this require any changes on OSV's end to support? If a compatible structure or set of conventions already exists for CVE-grouped advisories, we'd appreciate a pointer to it.
Handling existing records: Since this change restructures how we group vulnerabilities rather than deleting or altering existing advisory content, how should we handle the transition on OSV.dev's side? Specifically, how does OSV.dev expect us to manage the relationship between old package-wise advisory IDs and new CVE-wise ones (e.g. via
related,withdrawn, or another mechanism), so that deduplication and matching continue to work correctly?Any guidance here would be really helpful before we start migrating.
Thanks!
--------- Related Labels ------------