EUVD support in GHSA
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Tranquilla
- Stack tecnologico
- github
- Ambito
- security
Direzione di ricerca
Non sono indicati file, test o punti di ingresso. Inizia esaminando come il database degli avvisi e Dependabot consumano attualmente i dati GHSA e CVE, quindi esamina l’API EUVD e i requisiti degli identificatori. Per poter considerare il lavoro completato sarebbero necessari un ambito di supporto definito e un piano di implementazione concordato, che questa issue non fornisce ancora.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hello,
Yesterday I have commented an old issue, but I think it is better to open a new one :) (https://github.com/github/advisory-database/issues/5745)
According to the CRA (Cyber Resilience Act) requirements, generating an SBOM — and therefore performing vulnerability scanning — will become mandatory by the end of the year (September 2026 at the time of writing). As far as I understand, Dependabot relies on the GHSA database to detect vulnerabilities.
It would be highly valuable for European developers if GitHub could also support the EUVD, since the CRA mandates the use of EUVD instead of CVE. GitHub + GHSA + Dependabot already form a strong native tooling stack for automated vulnerability scanning, without requiring external tools — most of which currently do not support EUVD either.
The commonly mentioned issue is that the EUVD API is not well documented and currently only exposes CVE-based entries, but the database is expected to be populated with EUVD identifiers once the CRA becomes applicable. So yes, today EUVD is a « copy » of CVE IDs but later EUVD IDs would be unique and not in the CVE database.
I’m commenting this ticket to ask for your thoughts regarding potential EUVD support.
Is this something you are considering, and if so, is it planned before September 2026?
Thanks in advance.
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 2.5k
- Fork
- 772
- Merge medio
- 3g 15h
- PR unite (30g)
- 46
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/advisory-database
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#9255 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#9164 · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8994 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#8898 · 4 commenti · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8841 ·
Tutte le issue di github/advisory-database
Issue simili
-
good first issue
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 95/100
AOSSIE-Org/DebateAI#582 · 2 commenti ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
oasisprotocol/oasis-sdk#2523 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
cost:cheap severity:medium
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
fairagro/m4.2_sql_to_arc#227 ·