Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Microsoft CSAF in the sources #84

Open
Rafiot opened this issue Nov 13, 2024 · 4 comments
Open

Add Microsoft CSAF in the sources #84

Rafiot opened this issue Nov 13, 2024 · 4 comments
Assignees
Labels
enhancement New feature or request

Comments

@Rafiot
Copy link
Collaborator

Rafiot commented Nov 13, 2024

https://msrc.microsoft.com/csaf/provider-metadata.json

@Rafiot Rafiot self-assigned this Nov 13, 2024
@jonite
Copy link

jonite commented Nov 15, 2024

While adding MSFT, could you also add NCSC-NL CSAF?
https://vulnerabilities.ncsc.nl/csaf/

@adulau adulau added the enhancement New feature or request label Nov 16, 2024
@cedricbonhomme
Copy link
Collaborator

While adding MSFT, could you also add NCSC-NL CSAF? https://vulnerabilities.ncsc.nl/csaf/

Just to mention that we do have sightings from NCSC-NL:
https://vulnerability.circl.lu/sightings/?query=ncsc

@Rafiot
Copy link
Collaborator Author

Rafiot commented Nov 19, 2024

That's what happen when trying to load Microsoft CSAF, investigating further.

{"time":"2024-11-19T14:41:39+01:00","level":"INFO","msg":"AdvisoryFileProcessor.Process: \"https://msrc.microsoft.com/csaf/changes.csv\" has an invalid time stamp in line 91: parsing time \"2024-11-12T08:00:00.0000000\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"\" as \"Z07:00\""}

gocsaf/csaf#588

@Rafiot
Copy link
Collaborator Author

Rafiot commented Nov 19, 2024

@jonite just checking, in case ou know: the CSAF from NCSC NL seems to be a clone of the NVD. Is there anything else in there?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

4 participants