Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Collect (or re-collect) openSUSE and SUSE #84

Open
pombredanne opened this issue Sep 26, 2019 · 0 comments
Open

Collect (or re-collect) openSUSE and SUSE #84

pombredanne opened this issue Sep 26, 2019 · 0 comments
Labels
Data collection sys system or OS packages

Comments

@pombredanne
Copy link
Member

pombredanne commented Sep 26, 2019

We should revisit SUSE and OpenSUSE data.

  1. there are new feeds at https://www.suse.com/support/security/
  2. in particular there are now possibly overlapping CVRF, CSAF, VEX, and OSV formats at https://ftp.suse.com/pub/projects/security/ as well as scores in YAML format. These files and dirs are of interest:
csaf/                                              16-Nov-2024 10:39       -
csaf-vex/                                          16-Nov-2024 05:10       -
cvrf/                                              17-Nov-2024 10:30       -
cvrf-cve/                                          17-Nov-2024 03:41       -
cvrf1.2/                                           17-Nov-2024 10:30       -
osv/                                               16-Nov-2024 12:42       -
oval/                                              17-Nov-2024 05:32       -
yaml/                                              17-Nov-2024 09:31       -
csaf-vex.tar.bz2                                   16-Nov-2024 05:04    154M
csaf.tar.bz2                                       16-Nov-2024 11:06     76M
cvrf-cve.tar.bz2                                   01-Nov-2024 03:45    137M
cvrf.tar.bz2                                       16-Nov-2024 08:10    115M
cvrf1.2.tar.bz2                                    16-Nov-2024 09:05    117M
osv.tar.bz2                                        16-Nov-2024 12:43     15M
package2cpe.csv     
  1. distro downloads come with SBOMs like at https://updates.suse.com/SUSE/Products/SL-Micro/6.0/x86_64/iso/SL-Micro-6.0-Packages-x86_64-GM.cdx.json and https://www.suse.com/download/sle-micro/ both in SPDX and CycloneDX format
  2. There is also a list at [email protected]:
  1. See also Collect SUSE #62
@pombredanne pombredanne added the sys system or OS packages label Dec 3, 2019
This was referenced Sep 10, 2020
@pombredanne pombredanne changed the title Collect opensuse Collect (or re-collect) openSUSE and SUSE Nov 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Data collection sys system or OS packages
Projects
None yet
Development

No branches or pull requests

1 participant