-
Notifications
You must be signed in to change notification settings - Fork 605
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Using the information from cisa in grype #1511
Comments
is it possible to add it to the grype-db schema change that is planned in the future? |
this would be great a enrichment for the existing vulnerabilities |
can be relevant for here? anchore/grype-db#108 |
Indeed it will be part of the DB v6 work, which is currently being designed (and this feature is already be incorporated from a schema perspective) 🎉 What will need to happen after the schema lands is to update vunnel/grype-db to slurp in the data and populate it into the DB. |
Hi @wagoodman, we are curious about when this feature is scheduled for implementation. Is there a potential timeline? |
Right now we're working on releasing the v6 DB schema as the default schema in grype --this is a blocker to getting the cisa KEV data into the DB. The good news is that the v6 work will most likely be released this week if all goes well 🎉 ! I don't want to make any date promises but I think this could land on the order of weeks not months. |
What would you like to be added:
CISA provided information regarding if vulnerabilities were exploit.
it will be helpful to present or use this kind of information in grype. I saw we already sync this kind of information from NVD.
link - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Why is this needed:
Additional context:
The text was updated successfully, but these errors were encountered: