Red Hat and OSV Collaboration: Enhancing Vulnerability Transparency and Data Accessibility

OSV is an open format for describing software vulnerabilities, making it easier for security researchers, vendors, and consumers to exchange and understand vulnerability information. OSV.dev is a database that hosts and aggregates this data, promoting collaboration and facilitating the creation of vulnerability databases and tools.

Red Hat has collaborated with Google's OSV.dev and the OpenSSF to publish its security advisories in the OSV format. This enhances transparency and flexibility in consuming security advisories. Red Hat's collaboration includes expanding its existing disclosure formats and working with the OSV-Scanner team to support Red Hat containers.

The code for creating OSV data records is available in the OSV schema code repository, and the data can be accessed via OSV.dev, the OSV REST API, and the Red Hat Product Security Data site. Currently, OSV records focus on RPM content, but future releases will cover all content types. This initiative helps users better understand and manage Red Hat security vulnerabilities.

https://openssf.org/blog/2024/11/01/red-hats-collaboration-with-the-openssf-and-osv-dev-yields-results-red-hat-security-data-now-available-in-the-osv-format/

Comments

Popular posts from this blog

Endor Labs Announces Integrated SAST Offerings

OWASP Releases Enhanced Dependency-Check Tool with Advanced Tagging and Policy Management Features

The Hidden Cost of DevSecOps: Time and Financial Burden of Security on Developers