Re: political question about national vulnerability database and NIST

Paul Barker <[email protected]>
Newsgroups org.yoctoproject.lists.yocto
Message-ID <[email protected]>
On Mon, 2025-11-03 at 07:27 -0500, Robert P. J. Day wrote:
>   given that the NVD is run out of NIST, https://nvd.nist.gov/, are
> there any contingency plans for the trump administration simply
> defunding all of NIST? it seems like exactly the sort of thing they
> would do.

I was reading up on this a couple of weeks ago.

There was an independent CVE Foundation launched in April [1] in response to
worries about the funding of MITRE. I'm unsure what progress they have made
since MITRE funding was re-instated.

There was some response within OpenSSF [2], you may want to check in with them
to see what their current status is.

There's also the EU Vulnerability Database (EUVD) [3].

So, I think we're moving away from having a single point of failure, but like
all collaborative projects - more resources are probably welcome!

[1]: https://www.thecvefoundation.org/newsroom/posts/2025-04-16-launch
[2]: https://openssf.org/blog/2025/04/23/vulnerability-enumeration-conundrum-an-open-source-perspective-on-cve-and-cwe/
[3]: https://euvd.enisa.europa.eu

Cheers,

-- 
Paul Barker
signature.asc (application/pgp-signature, 252 B)
-----BEGIN PGP SIGNATURE-----

iIcEABYKAC8WIQSzjPXf5Y1BDWhU2iCrY1Tsnbr0bgUCaQiuShEccGF1bEBwYmFy
a2VyLmRldgAKCRCrY1Tsnbr0bmaxAPwPi4qFLU5eicNLLESjbSR7rKflLtY73p92
P3N2fotAbQEA8SS4LY3p5wpzNJIWMO5DK/3SDJNYKsAOGee6Ojo3qA4=
=pW8A
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.