Earlier quoted context omitted.
I’m a little hesitant to trust a CVE database operated by private industry on the grounds of conflict of interest for that reason, too.
I'm the opposite — and I think this might be the "4D chess"† interpretation of this move as well. In peacetime, I think everyone is generally alright with something centralized like the CVE database. But in what increasingly seems like the lead-up to wartime ... I'm hesitant to trust a CVE database operated or funded unilaterally by a single government — or even multilaterally, if the governments are all ones that al…
Work on supply chain security has lead to the introduction of standardized SBOMs, as an artifact required by some large customers to accompany software binaries. It should be possible to associate each software binary CVE with a vendor SBOM and organization country code. Large multinationals might have geo-specific binaries to confirm with regional regulations like the EU CRA.