Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Using the information from cisa in grype #1511

Open
tomerse-sg opened this issue Sep 21, 2023 · 6 comments
Open

Using the information from cisa in grype #1511

tomerse-sg opened this issue Sep 21, 2023 · 6 comments
Assignees
Labels
database Relating to the grype DB asset enhancement New feature or request
Milestone

Comments

@tomerse-sg
Copy link

What would you like to be added:
CISA provided information regarding if vulnerabilities were exploit.
it will be helpful to present or use this kind of information in grype. I saw we already sync this kind of information from NVD.
link - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Why is this needed:

  • prioritize vulnerabilities which were already exploit
  • more data about known vulnerabilities
    Additional context:
@tomerse-sg tomerse-sg added the enhancement New feature or request label Sep 21, 2023
@tomerse-sg
Copy link
Author

is it possible to add it to the grype-db schema change that is planned in the future?
it can be a cool enrichment

@alonmaor
Copy link

alonmaor commented Jul 1, 2024

this would be great a enrichment for the existing vulnerabilities
any update on this?

@tomerse-sg
Copy link
Author

can be relevant for here? anchore/grype-db#108

@wagoodman wagoodman added this to the DB v6 milestone Aug 7, 2024
@wagoodman wagoodman moved this to Ready in OSS Aug 7, 2024
@wagoodman
Copy link
Contributor

Indeed it will be part of the DB v6 work, which is currently being designed (and this feature is already be incorporated from a schema perspective) 🎉 What will need to happen after the schema lands is to update vunnel/grype-db to slurp in the data and populate it into the DB.

@wagoodman wagoodman added the database Relating to the grype DB asset label Aug 7, 2024
@hieunguyentr92
Copy link

Hi @wagoodman, we are curious about when this feature is scheduled for implementation. Is there a potential timeline?

@wagoodman wagoodman self-assigned this Feb 18, 2025
@wagoodman
Copy link
Contributor

Right now we're working on releasing the v6 DB schema as the default schema in grype --this is a blocker to getting the cisa KEV data into the DB. The good news is that the v6 work will most likely be released this week if all goes well 🎉 ! I don't want to make any date promises but I think this could land on the order of weeks not months.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
database Relating to the grype DB asset enhancement New feature or request
Projects
Status: In Review
Development

No branches or pull requests

4 participants