Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RHSA ID for vulnerabilities names instead of CVE ID #495

Closed
yebinama opened this issue Dec 7, 2017 · 3 comments
Closed

RHSA ID for vulnerabilities names instead of CVE ID #495

yebinama opened this issue Dec 7, 2017 · 3 comments
Labels
area/usability related to improving user experience

Comments

@yebinama
Copy link
Contributor

yebinama commented Dec 7, 2017

Hi,

Why did you choose to have RHSA ID (and ELSA for Oracle) as vulnerabilities names for Red Hat OSes instead of CVE-ID like Ubuntu or Alpine?
With RHSA ID as a name, vulnerabilities lack informations like NVD metadata and it's more difficult to know which images are affected by a specific CVE.

I think It would be nice to have the same behavior for all updaters.
If you are interested, I made a patch on my fork and can submit a merge request.

@jzelinskie
Copy link
Contributor

I don't recall a particular reason for that naming convention. You change sounds great. I'd love to review your patch and get it merged into the project.

@jzelinskie jzelinskie added area/usability related to improving user experience component/ext/vulnsrc labels Dec 13, 2017
@Quentin-M
Copy link
Contributor

Quentin-M commented Dec 14, 2017 via email

@yebinama
Copy link
Contributor Author

Thanks for the explanations.
We'll sure have to be careful to not break the consistency of the database that's why I asked for the reason of this naming convention :)

I made a patch based on release-2.0. Before submitting it, I have to made a few changes to get it to work on the master branch (probably next week).

yebinama added a commit to yebinama/clair that referenced this issue Dec 18, 2017
Get one vulnerability by CVE_ID for RHEL instead of one by RHSA_ID so we can have NVD metadata added to the vulnerabilities.

Fixes quay#495
yebinama added a commit to yebinama/clair that referenced this issue Sep 14, 2018
Get one vulnerability by CVE_ID for RHEL instead of one by RHSA_ID so we can have NVD metadata added to the vulnerabilities.

Fixes quay#495
glb added a commit to glb/clair that referenced this issue Nov 2, 2018
Get one vulnerability per CVE for Oracle instead of one per RHSA so we
can have NVD metadata added to the vulnerabilities.

Related: quay#495, quay#499.
glb added a commit to glb/clair that referenced this issue Nov 2, 2018
Get one vulnerability per CVE for Oracle instead of one per ELSA so we
can have NVD metadata added to the vulnerabilities.

Related: quay#495, quay#499.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/usability related to improving user experience
Development

No branches or pull requests

3 participants