Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for NIST/NVD 2.0 data feeds #4742

Open
2 tasks done
andham opened this issue Mar 10, 2025 · 1 comment
Open
2 tasks done

Support for NIST/NVD 2.0 data feeds #4742

andham opened this issue Mar 10, 2025 · 1 comment
Labels
enhancement New feature or request integration/nvd Related to the NVD integration p2 Non-critical bugs, and features that help organizations to identify and reduce risk size/M Medium effort

Comments

@andham
Copy link

andham commented Mar 10, 2025

Current Behavior

According to https://www.nist.gov/itl/nvd NIST has changed their mind and will not retire the NVD data feeds, but create new NVD 2.0 data feeds.

Proposed Behavior

In some environments (air-gapped and similar) it is much easier to create mirror sites for these data feeds than the NVD APIs, so support for the new 2.0 data feeds would be great.

Checklist

@andham andham added the enhancement New feature or request label Mar 10, 2025
@nscuro
Copy link
Member

nscuro commented Mar 10, 2025

For future reference, the relevant part of the provided link is this:

Legacy Data Feed Files Update
We are planning to retire and replace the following legacy data feed files with complimentary data feed files that reflect the 2.0 /cves/, /cpematch/ and /cpes/ API response content.

While we originally intended to move away from supporting this type of bulk download capability, circumstances have redirected our efforts from other, preferred approaches.

Once these updates are made available, the unsupported legacy data feed files will remain available in parallel for 3 months as a courtesy. After that time, the legacy 1.1 feed files will no longer be accessible. Any organizations making use of the legacy feed files will need to update their systems to use the 2.0 APIs or the 2.0 data feed files.

@nscuro nscuro added p2 Non-critical bugs, and features that help organizations to identify and reduce risk size/M Medium effort integration/nvd Related to the NVD integration labels Mar 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request integration/nvd Related to the NVD integration p2 Non-critical bugs, and features that help organizations to identify and reduce risk size/M Medium effort
Projects
None yet
Development

No branches or pull requests

2 participants