Skip to content

Update Fleet to use new NVD format for vulnerabilities (CVEs) #14824

Description

@lukeheath

Goal

User story
As a Fleet engineer,
I want to update our NVD CPE data feed,
so that I can continue to update CPE data in Fleet.

NOTE: This must be included in 4.41.0, as vulnerability scanning will stop working for all Fleet instances on 12/15. We need to release no later than 4.41.0 so that customers and the community have time to upgrade before 12/15.

Changes

Product

There should be no visible changes to the product as a result of this user story.

Engineering

  • Evaluate NIST NVD 2.0 API.
  • Spec changes necessary to ingest data from 2.0 API.
  • Create and estimate sub-tasks.

Context

QA

Manual testing steps

TODO @xpkoala

Testing notes

Confirmation

  1. Engineer (@____): Added comment to user story confirming succesful completion of QA.
  2. QA (@____): Added comment to user story confirming succesful completion of QA.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

#g-endpoint-opsEndpoint ops product group:productProduct Design department (shows up on 🦢 Drafting board)storyA user story defining an entire feature~release blockerThis story is currently blocking the next release of Fleet from going out.

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions