Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE published date field available in the report #1355

Open
stefaniuk opened this issue Jun 21, 2023 · 9 comments
Open

CVE published date field available in the report #1355

stefaniuk opened this issue Jun 21, 2023 · 9 comments
Labels
enhancement New feature or request

Comments

@stefaniuk
Copy link

What would you like to be added:

We would like to request an additional filed(s) to be added to the report produced by grype that would enable us to tell when a CVE has been published and last updated.

Why is this needed:

Currently this information doesn't seem to be available in the JSON output.

Additional context:

This is for the purpose of reporting.

@stefaniuk stefaniuk added the enhancement New feature or request label Jun 21, 2023
@spiffcs spiffcs added this to OSS Jun 22, 2023
@spiffcs spiffcs mentioned this issue Jun 22, 2023
@kzantow
Copy link
Contributor

kzantow commented Jun 22, 2023

This looks like a great addition and we'll look to add this to Grype! It looks like we're reading this information from NVD but we would need to update the Grype DB to get it included; we'll add this to the backlog. Thanks for bringing this to our attention!

@kzantow kzantow moved this to Backlog in OSS Jun 22, 2023
@kzantow
Copy link
Contributor

kzantow commented Jun 22, 2023

Hey @westonsteimel do you have any other thoughts on this?

@wawadevops
Copy link

It will be a huge enhancement. Looking forward to this feature.

@matheusfm
Copy link

+1

@brianwcook
Copy link

+1 - this would make it possible to apply CVE fix SLAs.

@benjaminwilcox
Copy link

+1

@rulas
Copy link

rulas commented Dec 11, 2024

+1, this is a must-have. Specially to prioritize issues by age.

@ogomezg0106
Copy link

Getting to include CVE Published Date from NVD would help a lot in order to automate results report content.

@Noclas
Copy link

Noclas commented Dec 11, 2024

+1, this would help to work properly with SLAs regarding a given CVE.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: Backlog
Development

No branches or pull requests

9 participants