Red Hat and OSV Collaboration: Enhancing Vulnerability Transparency and Data Accessibility
OSV is an open format for describing software vulnerabilities, making it easier for security researchers, vendors, and consumers to exchange and understand vulnerability information. OSV.dev is a database that hosts and aggregates this data, promoting collaboration and facilitating the creation of vulnerability databases and tools.
Red Hat has collaborated with Google's OSV.dev and the OpenSSF to publish its security advisories in the OSV format. This enhances transparency and flexibility in consuming security advisories. Red Hat's collaboration includes expanding its existing disclosure formats and working with the OSV-Scanner team to support Red Hat containers.
The code for creating OSV data records is available in the OSV schema code repository, and the data can be accessed via OSV.dev, the OSV REST API, and the Red Hat Product Security Data site. Currently, OSV records focus on RPM content, but future releases will cover all content types. This initiative helps users better understand and manage Red Hat security vulnerabilities.
https://openssf.org/blog/2024/11/01/red-hats-collaboration-with-the-openssf-and-osv-dev-yields-results-red-hat-security-data-now-available-in-the-osv-format/
Comments
Post a Comment