osv.dev icon indicating copy to clipboard operation
osv.dev copied to clipboard

Requesting for New datasource: CleanStart Security Advisory

Open cleanstart-community-admin opened this issue 2 months ago • 5 comments

Hello there, OSV.

CleanStart is (https://www.cleanstart.com/) comprehensive software supply chain security solution designed to address the most critical challenges facing modern container deployments. At its core, CleanStart provides hardened, vulnerability-free container images built on our proprietary glibc-compatible base.

‍CleanStart provides comprehensive security advisories for zero-day vulnerabilities, delivering clear, actionable information that enables informed response decisions. These advisories include multiple information elements including vulnerability description, affected components, exploitation status, actual risk assessment, available mitigations, and remediation guidance with complete details rather than vague summaries.

We are looking forward to contribute to global vulnerability data. On behalf of the company, I am requesting to have CleanStart as recognized ecosystem in OSV database, and guide us to contribute as per the OSV standard.

Ecosystem: CLEANSTART ID Format: CLEANSTART-YYYY-AZNNNNN CleanStart Security Advisory Repository: https://github.com/cleanstart-dev/cleanstart-security-advisories CleanStart Community Images: https://hub.docker.com/u/cleanstart

Thank you, CleanStart Security. https://www.cleanstart.com/

Status check of actionable items:

May I get any update on the request generated above?

Please link the PRs sent to this issue (or from this issue).

[PR Sent] Create a PR to reserve an ID prefix and define a new ecosystem (https://github.com/ossf/osv-schema/pull/219). We review the records you start publishing for OSV Schema correctness and quality as part of reviewing and merging this PR.

I'm not seeing this PR?

CleanStart Security Advisory Repository: https://github.com/cleanstart-dev/cleanstart-security-advisories

Thanks! Looks pretty good, just one change, instead of putting the CVE and PSF records in aliases, they should go in the upstream field. You can also safely exclude the Bitnami records from the alias field (or keep them, both should compute to the same result).

another-rex avatar Oct 26 '25 23:10 another-rex

Hello @another-rex , From CleanStart we appreciate your efforts for the review and reply.

Please find PR as requested: https://github.com/ossf/osv-schema/pull/447

Also we have updated the CleanStart Security Advisory Repository as per your suggestions. Please find it at https://github.com/cleanstart-dev/cleanstart-security-advisories

Please review our request again, and revert.

Thank you, CleanStart Security.

May I get any update on the changes made as requested?

Hi @cleanstart-community-admin ! @another-rex is currently OOO and expect to be back next week - your changes will be reviewed once he is back.

cuixq avatar Nov 05 '25 21:11 cuixq