diff --git a/README.md b/README.md index 9dc5ae6..6a8e56b 100644 --- a/README.md +++ b/README.md @@ -1,19 +1,35 @@ # Debian ELTS Advisories -This repository contains security advisories for Debian LTS in JSON format. +## Background -TODO: +- Debian LTS is maintained by the Debian Security team +- Debian Extended LTS, a commercial offering is maintained by Freexian. +- Debian ELTS Advisories are announced at https://www.freexian.com/lts/extended/updates/ +- [OSV](https://ossf.github.io/osv-schema/) is a Open Source Vulnerability format, as specified by the [Open Source Security Foundation](https://openssf.org). +- [GSD Database](https://globalsecuritydatabase.org/) is a vulnerability database used by OSV.dev, and maintained by the [Cloud Security Alliance](https://cloudsecurityalliance.org/) -- [ ] The data is automatically updated. -- [ ] This will be synced to the GSD repository -- [ ] Switch to the OSV format. +## What is this project? + +The OSV.dev expects advisories to be published in the OSV format. This repository +republishes the advisories in the OSV format, and syncs them against the +[GSD Database](https://github.com/cloudsecurityalliance/gsd-database) + +- [x] Picks up data from [extended-lts-security-tracker][source] +- [x] Generates advisories in the OSV format at advisories/ +- [ ] Syncs Data to the GSD Database + +## TODO + +- [ ] Add Credits ## Source: -- Updates are fetched from the LTS Announcements: https://www.freexian.com/lts/extended/updates/ -- as listed via the [Sitemap](https://www.freexian.com/sitemap.xml) +- Updates are fetched from the ELTS Security Tracker: - The data is also published at https://deb.freexian.com/extended-lts/tracker/data/json, but it doesn't include the announcement URLs, and harder to use. +- See https://github.com/ossf/osv-schema/pull/104 for more information. ## License -The code is licensed under MIT. \ No newline at end of file +The code is licensed under MIT. + +[source]: https://salsa.debian.org/freexian-team/extended-lts/security-tracker/-/blob/master/data/ELA/list \ No newline at end of file