Include Vendor Advisory Date #7313
Hacks4Snacks
started this conversation in
Ideas
Replies: 1 comment
-
Thanks for your idea. Please let us see how much the community needs this feature. To the community: Please leave a comment or reaction. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Description:
There are some vendors (such as Azure Linux) that provide “advisory date” metadata in their vulnerability datasets. Exposing this data in Trivy’s vulnerability reports would be highly beneficial for users.
Justification:
The “advisory date” indicates when a vulnerability advisory was first published for a given vendor instead of NVD CVE publication. This information is crucial for several reasons:
Impact on Existing Workflows:
Integrating the “advisory date” into the existing outputs should be seamless, requiring minimal changes to current workflows. Users can leverage this additional data point without significant alterations to their existing vulnerability management processes.
Target
None
Scanner
Vulnerability
Beta Was this translation helpful? Give feedback.
All reactions