Security News > 2021 > June > Google Expands Open Source Vulnerabilities Database

Google Expands Open Source Vulnerabilities Database
2021-06-24 13:52

Google today announced the expansion of the Open Source Vulnerabilities database to include information on bugs identified in Go, Rust, Python, and DWF open source projects.

Launched in February 2021 with details on thousands of vulnerabilities from Google's OSS-Fuzz project, the OSV database is meant to provide automated, improved vulnerability triage for both developers and users of open source software.

The aggregation of these databases also comes with a unified schema for describing vulnerabilities, which aims to address key issues related to the management of vulnerabilities in open source.

No standard format was found which would enforce version specification to precisely match naming and versioning schemes used in open source ecosystems, which could be used to describe vulnerabilities in any ecosystem, and which would be easy to use by humans and automated systems alike.

The new schema, Google says, should deliver a unified format for all vulnerability databases, offer a more comprehensive view of flaws in open source software, improve detection and remediation, and make it easy for databases, users, and security researchers to share tooling.

To automate maintenance of the vulnerability database, Google has built tools not only for OSV, but also for the community Python advisory database, and plans on expanding these tools to other ecosystems for which a vulnerability database does not exist or exists but is not properly maintained.


News URL

http://feedproxy.google.com/~r/securityweek/~3/QqicJdoD1wY/google-expands-open-source-vulnerabilities-database

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 994 4922 2872 1623 10411