Replies: 4 comments 6 replies
-
|
@kmoens I came to ask a very similar question to yours. This is how our credit utilization look like
And all I see in the vulnerabilities we have are mostly ones tagged with "NVD". Nothing having "OSSINDEX" like the screenshot in the documentation
|
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
|
@nscuro Are you aware of an alternative analyser that can be used? Our usage is even higher than above. I have tried the Trivy one previously, but it generates a very different set of results. Our usage averages 95k/month!!!! |
Beta Was this translation helpful? Give feedback.
-
|
Hi @nscuro. Currently as we have bust our limit on Sonatype (Average 95k per month!!!!) Why is DT not showing any vulnerabilities from NVD? Thanks |
Beta Was this translation helpful? Give feedback.



Uh oh!
There was an error while loading. Please reload this page.
-
Hello guys,
We are currently using the OSS Index, but based on the credits they will give we'll have to either start using their enterprise plan, or look for alternatives, due to our extimated usage of the credits.
We currently have NVD, Google OSV, GitHub Advisories and OSS Index enabled. For our projects we don't see the Sonatype reported vulnerabilities, only the CVEs, but looking at the API calls, they are found by means of the OSS Index.
From what I see, most of these vulnerabilities also have aliases in the GitHub Advisories, and they are nicely added.
Do I expect to loose information if we disable the OSS Index? Our ecosystem is mainly Java and TypeScript.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions