Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Import container/helm vulnerabilities from ArtifactHub.io #2666

Open
taraspos opened this issue Sep 24, 2024 · 1 comment
Open

Import container/helm vulnerabilities from ArtifactHub.io #2666

taraspos opened this issue Sep 24, 2024 · 1 comment
Assignees
Labels
backlog Important but currently unprioritized datasource Requests for new data sources enhancement New feature or request

Comments

@taraspos
Copy link

taraspos commented Sep 24, 2024

Is your feature request related to a problem? Please describe.
Currently, osv.dev doesn't have much information about container image vulnerabilities.

At the same time Artifacthub.io runs trivy to scan container images1, would be great to be able to see vulnerability information collected by Artifacthub in osv.dev.

Describe the solution you'd like
Integrate Artifacthub as datasource for vulnerabilities using Security Report API2

Describe alternatives you've considered
Fetching vulnerability information directly form ArtifactHub API2

Additional context

Footnotes

  1. https://artifacthub.io/docs/topics/security_report/

  2. https://artifacthub.io/docs/api/#/Packages/getPackageSecurityReport 2

@andrewpollock
Copy link
Contributor

Thanks for the endorsement and for raising this with Artifacthub.io as well. We're largely dependent on them choosing to publish OSV records before we can move this forward...

@andrewpollock andrewpollock added datasource Requests for new data sources backlog Important but currently unprioritized labels Sep 27, 2024
@andrewpollock andrewpollock self-assigned this Sep 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backlog Important but currently unprioritized datasource Requests for new data sources enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants