Re: Usage of Suse Security Data in VulnerableCode

Alexander Bergmann <[email protected]> Tue, 10 Jan 2023 16:33:46 +0100
Newsgroups gmane.linux.suse.security
Message-ID <20230110153346.kc2yw3cgqxofsnu2@castor>
--urrx2anxttirho3e
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi Tushar,

Thanks for reaching out and your interest into our CVSS scoring.

Right now I couldn't find any license reference to the YAML file you've
linked, but it should be the same as our OVAL data that is under the
Creative Commons License 4.0 with Attribution (CC-BY-4.0), and also
includes the CVSS score.

https://www.suse.com/support/security/oval/

I try to find out about the YAML file as well, but this could take a
couple days.


Best regards,
Alex~

On Tue, Jan 10, 2023 at 01:05:23PM -0000, Tushar Goel wrote:
> Hey,
>=20
> We would like to integrate the suse backport [1][2]=20
> and suse scoring [3][4] data in vulnerablecode
> [5] which is a FOSS db of FOSS vulnerability data. We were not able
> to know under which license this security data comes. We would
> be grateful to have your acknowledgement over usage of the suse
> security data in vulnerablecode and have some kind of licensing
> declaration from your side.
> [1] - http://ftp.suse.com/pub/projects/security/yaml/
> [2] - https://github.com/nexB/vulnerablecode/pull/1053
> [3] - https://ftp.suse.com/pub/projects/security/yaml/suse-cvss-scores.ya=
ml
> [4] - https://github.com/nexB/vulnerablecode/pull/1050
> [5] - https://github.com/nexB/vulnerablecode
>=20
> Regards,

--=20
Alexander Bergmann <[email protected]>
Security Engineer, GPG: E30A 65A4 0F50 0066 B2B5  F614 DE54 E875 9FFA 4886
SUSE Software Solutions Germany GmbH
Maxfeldstr. 5, 90409 Nuremberg, Germany
(HRB 36809, AG N=FCrnberg)
Managing Director/Gesch=E4ftsf=FChrer: Ivo Totev, Andrew Myers, Andrew McDo=
nald, Boudien Moerman

--urrx2anxttirho3e
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAABCAAdFiEE4wplpA9QAGaytfYU3lTodZ/6SIYFAmO9hVgACgkQ3lTodZ/6
SIay3AgAiI3vTQmCf5aCQZYIGLiT3GKx9at2fv3k9zAQe5ZTdS+OMcR+L5wOIXyq
rDkSvJFGLGJ0p6/Q1tsffWDLBA0r99lwhn/RJPRF6Z8ZNi4EP5Y02D0/RMOjZ5d1
chuf7lCkYBbGfUydujOWSu0ruFW/F1OttplKtKlI4eXVzFQ5GVb9uuzg8/5EGQce
ovssVhwfhab6p/3B8zaPCpcos/hAYlSvgMqnPC+ahHYk/sbGIRtYezPW1uk5zExC
FIU4QFeZiq3loP6J5OgHLKNdVPEpztfXaPVEclkzbdWb1tOobllNKZQ7iGdn8pdM
s2i+qEpTrKpvHwZDH9A7ZOsSt0LqpQ==
=bIXg
-----END PGP SIGNATURE-----

--urrx2anxttirho3e--