Skip to content

Conversation

hasnatbashir
Copy link

Related issue: anchore/grype-db#644

Copy link
Contributor

@wagoodman wagoodman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The goal here is to add a new CWEs table instead of adding CWEs to the vulnerability blob, that way we can use CWEs across multiple providers in theory (same way KEVs are portrayed, as their own table) ... see anchore/grype-db#644 (comment)

@hasnatbashir
Copy link
Author

@wagoodman Thanks! Could you also clarify the representation? What should the schema look like, right now we just want to store a list of CWEs against CVE IDs Would a simple schema be sufficient? or should we use a blob format, like other handles, to keep it flexible in case we want to store additional fields in the future?

@willmurphyscode willmurphyscode self-assigned this Sep 3, 2025
@willmurphyscode willmurphyscode moved this to In Review in OSS Sep 3, 2025
@hasnatbashir
Copy link
Author

@wagoodman can you please take a look again?

@hasnatbashir
Copy link
Author

@willmurphyscode Can you please take a look at this PR? Let me know if there are any other changes that are needed?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: In Review
Development

Successfully merging this pull request may close these issues.

3 participants