Files
trivy/docs/vulnerability/detection/data-source.md
afdesk 5d57deaa4f fix(docs): remove OSVDB advisories (#1215)
Trivy no longer depends on OSVDB and can use "Ruby Advisory Database" for commercial usage.

Fixes #1208
2021-09-05 08:39:10 +03:00

4.3 KiB

OS

OS Source
Arch Linux Vulnerable Issues
Alpine Linux secdb
Amazon Linux 1 Amazon Linux Security Center
Amazon Linux 2 Amazon Linux Security Center
Debian Security Bug Tracker
OVAL
Ubuntu Ubuntu CVE Tracker
RHEL/CentOS OVAL
Security Data
Oracle Linux OVAL
OpenSUSE/SLES CVRF
Photon OS Photon Security Advisory

Programming Language

Language Source Commercial Use Delay1
PHP PHP Security Advisories Database -
GitHub Advisory Database (Composer) -
Python Safety DB 1 month
GitHub Advisory Database (pip) -
Ruby Ruby Advisory Database -
GitHub Advisory Database (RubyGems) -
Node.js Ecosystem Security Working Group -
GitHub Advisory Database (npm) -
Java GitLab Advisories Community 1 month
GitHub Advisory Database (Maven) -
Go GitLab Advisories Community 1 month
The Go Vulnerability Database -
Rust RustSec Advisory Database -
.NET GitHub Advisory Database (NuGet) -

Others

Name Source
National Vulnerability Database NVD

  1. Intentional delay between vulnerability disclosure and registration in the DB ↩︎