Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CPE, PURL, versioning discussions for vulnerability-lookup #78

Open
6 tasks
adulau opened this issue Oct 21, 2024 · 0 comments
Open
6 tasks

CPE, PURL, versioning discussions for vulnerability-lookup #78

adulau opened this issue Oct 21, 2024 · 0 comments
Assignees
Labels
enhancement New feature or request

Comments

@adulau
Copy link
Member

adulau commented Oct 21, 2024

Following some discussions, notes about versioning in vulnerability-lookup:

  • Improve the UI output with the version is available next to the product name.
  • Improve the CPE api to search for product/vendor to be originally compatible with the original cve-search API.
  • Add cpe-guesser directly in vulnerability-lookup.
  • Add ability to extend or alias CPE name such as new vendor names or product names.
  • Review the additional CPE from other users (like JPN).
  • Support of purl export if a package name is known.

Ref: package-url/purl-spec#331

@adulau adulau added the enhancement New feature or request label Oct 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants