Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

EUVD support in GHSA

オープン
#7,285 コメント 0 件 リアクション 4 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
25/100
issue の種類
機能追加
明瞭さ
説明が足りない
活発さ
静か
技術スタック
github
領域
security

調査の方向性

ファイル、テスト、エントリポイントは指定されていません。まず、advisory database と Dependabot が現在 GHSA および CVE データをどのように利用しているかを確認し、その後 EUVD API と識別子の要件を調査してください。完了とするには、サポート範囲の定義と合意済みの実装計画が必要ですが、この issue にはまだそれらがありません。

索引モデルが issue の本文から書いたものです。

説明

Hello,

Yesterday I have commented an old issue, but I think it is better to open a new one :) (https://github.com/github/advisory-database/issues/5745)

According to the CRA (Cyber Resilience Act) requirements, generating an SBOM — and therefore performing vulnerability scanning — will become mandatory by the end of the year (September 2026 at the time of writing). As far as I understand, Dependabot relies on the GHSA database to detect vulnerabilities.

It would be highly valuable for European developers if GitHub could also support the EUVD, since the CRA mandates the use of EUVD instead of CVE. GitHub + GHSA + Dependabot already form a strong native tooling stack for automated vulnerability scanning, without requiring external tools — most of which currently do not support EUVD either.

The commonly mentioned issue is that the EUVD API is not well documented and currently only exposes CVE-based entries, but the database is expected to be populated with EUVD identifiers once the CRA becomes applicable. So yes, today EUVD is a « copy » of CVE IDs but later EUVD IDs would be unique and not in the CVE database.

I’m commenting this ticket to ask for your thoughts regarding potential EUVD support.
Is this something you are considering, and if so, is it planned before September 2026?

Thanks in advance.

主要言語
言語のデータがありません
スター
2.5k
フォーク
772
平均マージ
3日 15時間
マージ済み PR(30日)
46

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/advisory-database のほかの issue

github/advisory-database の issue をすべて見る

似ている issue

Security の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。