debian-elts-advisories/README.md

35 lines
1.5 KiB
Markdown
Raw Permalink Normal View History

2023-01-04 14:10:18 +00:00
# Debian ELTS Advisories
2023-01-05 12:45:44 +00:00
## Background
2023-01-04 14:10:18 +00:00
2023-01-05 12:45:44 +00:00
- Debian LTS is maintained by the Debian Security team
- Debian Extended LTS, a commercial offering is maintained by Freexian.
- Debian ELTS Advisories are announced at https://www.freexian.com/lts/extended/updates/
- [OSV](https://ossf.github.io/osv-schema/) is a Open Source Vulnerability format, as specified by the [Open Source Security Foundation](https://openssf.org).
- [GSD Database](https://globalsecuritydatabase.org/) is a vulnerability database used by OSV.dev, and maintained by the [Cloud Security Alliance](https://cloudsecurityalliance.org/)
2023-01-04 14:10:18 +00:00
2023-01-05 12:45:44 +00:00
## What is this project?
The OSV.dev expects advisories to be published in the OSV format. This repository
republishes the advisories in the OSV format, and syncs them against the
[GSD Database](https://github.com/cloudsecurityalliance/gsd-database)
- [x] Picks up data from [extended-lts-security-tracker][source]
- [x] Generates advisories in the OSV format at advisories/
- [ ] Syncs Data to the GSD Database
## TODO
- [ ] Add Credits
2023-01-04 14:10:18 +00:00
## Source:
2023-01-05 12:45:44 +00:00
- Updates are fetched from the ELTS Security Tracker:
2023-01-04 14:10:18 +00:00
- The data is also published at https://deb.freexian.com/extended-lts/tracker/data/json, but it doesn't include the announcement URLs, and harder to use.
2023-01-05 12:45:44 +00:00
- See https://github.com/ossf/osv-schema/pull/104 for more information.
2023-01-04 14:10:18 +00:00
## License
2023-01-05 12:45:44 +00:00
The code is licensed under MIT.
[source]: https://salsa.debian.org/freexian-team/extended-lts/security-tracker/-/blob/master/data/ELA/list