Skip to content

Enable OSV vulnerability source per default #5343

@nscuro

Description

@nscuro

Current Behavior

We previously enabled the OSS Index analyzer per default, since it allowed for unauthenticated usage.

The other vulnerability source that is enabled per default is the NVD. It however does not provide PURL matching data and is thus not of great help during vulnerability analysis.

We need another, PURL-based alternative that can be enabled per default.

Proposed Behavior

Enable the OSV integration per default.

It provides PURL matching data, does not require authentication, and has broad ecosystem coverage.

Consider limiting the default to a small selection of popular ecosystems.

Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestp2Non-critical bugs, and features that help organizations to identify and reduce risksize/SSmall effort

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions