Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

WH Theme: SBOMS /  Notifications

  • See SBOM page
  • Consider adopting Look at providing vulnerability data in a format that can be combined with SBOM such as VEX (CSAF) and/or OSV  https://osv.dev/(instead of CVE/CVSS). (These are not mutually exclusive)
  • We have no way to know who is using our projects, nor do we want to capture that data (so is the current vulnerability notification system sufficient?)

...