vulnerablecode icon indicating copy to clipboard operation
vulnerablecode copied to clipboard

Add data in CSAF format from https://github.com/cisagov/CSAF

Open pombredanne opened this issue 1 year ago • 7 comments

reported by @mjherzog

We should add data in CSAF format from https://github.com/cisagov/CSAF

Note:

  • there may be several devices we may not care for in these data
  • https://github.com/oasis-tcs/csaf supports both PURLs and VERS but that does not men that the CISA included them in their docs

See also:

  • https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html
  • https://www.cisa.gov/news-events/news/transforming-vulnerability-management-cisa-adds-oasis-csaf-20-standard-ics-advisories

pombredanne avatar Oct 03 '23 09:10 pombredanne

@pombredanne I think there are 1940 json files of CSAF data as its mentioned in their "index.txt" file. How do you want to add it to our project. Can you please provide more details.

tehami02 avatar Oct 12 '23 04:10 tehami02

Hi @pombredanne can you please assign this issue to me, so I can start working on it

aryangupta701 avatar Jan 15 '24 14:01 aryangupta701

@aryangupta701 we do not "assign" issues except for core team members :) ... You can just state here that you are working on it and this is enough for a start and thank you ++ for this BTW.

pombredanne avatar Jan 15 '24 15:01 pombredanne

@tehami02 re

I think there are 1940 json files of CSAF data as its mentioned in their "index.txt" file. How do you want to add it to our project. Can you please provide more details.

We would import these CSAF data file as advisories, vulnerabilities and packages in our DB. That's the whole point of this issue.

pombredanne avatar Jan 15 '24 15:01 pombredanne

Okay I am working on this issue. Thank you

aryangupta701 avatar Jan 15 '24 16:01 aryangupta701

@ziadhany exactly what we need to do in this one, we have to make a simple importer or some kind of api, if api then what should be the endpoint?

ambuj-1211 avatar May 20 '24 14:05 ambuj-1211

@ambuj-1211 I think we need to import CSFA data and also support the vulnerability CSAF format

ziadhany avatar May 20 '24 15:05 ziadhany