Live data from Hacker News

Security advisories and JSA-2020-0001

community.jitsi.org

1–4 of 4 posts

Re: Security advisories and JSA-2020-0001

#2
Side note: I wish there was an accepted industry-wide, machine-readable format for security advisories. It's kind of a pain that every project out there defines their own way, ranging from atrocious blog posts:

https://chromereleases.googleblog.com/2020/02/stable-channel...

to plain text files:

http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.t...

or custom XMLs:

https://www.openssl.org/news/vulnerabilities.xml

The CVRF standard promised to be this but is largely unused since it's fairly rigid and requires a lot of investment to get it right.

Even GitHub's advisories are fairly limited in the metadata they provide and only accessible through the GraphQL API.

Re: Security advisories and JSA-2020-0001

#3
post #2

Side note: I wish there was an accepted industry-wide, machine-readable format for security advisories. It's kind of a pain that every project out there defines their own way, ranging from atrocious blog posts: https://chromereleases.googleblog.com/2020/02/stable-channel... to plain text files: http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.t... or custom XMLs: https://www.openssl.org/news/vulnerabilities…

What about CVE+CPE? The NIST NVD provides a CVE+CPE API for your machine readable format, and CVE's are collected by MITRE.

Re: Security advisories and JSA-2020-0001

#4
post #2

Side note: I wish there was an accepted industry-wide, machine-readable format for security advisories. It's kind of a pain that every project out there defines their own way, ranging from atrocious blog posts: https://chromereleases.googleblog.com/2020/02/stable-channel... to plain text files: http://web.mit.edu/Kerberos/advisories/MITKRB5-SA-2015-001.t... or custom XMLs: https://www.openssl.org/news/vulnerabilities…

What about CVE+CPE? The NIST NVD provides a CVE+CPE API for your machine readable format, and CVE's are collected by MITRE.

Yes, but which open source project publishes CPEs for their vulnerability information? :-) Plus, an important part of every security advisory is specifying which versions are affected by a particular vulnerability versus which contain the fix and are thus no longer affected.