Re: political question about national vulnerability database and NIST
Paul Barker <[email protected]>
| Newsgroups | org.yoctoproject.lists.yocto |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 2025-11-03 at 07:27 -0500, Robert P. J. Day wrote: > given that the NVD is run out of NIST, https://nvd.nist.gov/, are > there any contingency plans for the trump administration simply > defunding all of NIST? it seems like exactly the sort of thing they > would do. I was reading up on this a couple of weeks ago. There was an independent CVE Foundation launched in April [1] in response to worries about the funding of MITRE. I'm unsure what progress they have made since MITRE funding was re-instated. There was some response within OpenSSF [2], you may want to check in with them to see what their current status is. There's also the EU Vulnerability Database (EUVD) [3]. So, I think we're moving away from having a single point of failure, but like all collaborative projects - more resources are probably welcome! [1]: https://www.thecvefoundation.org/newsroom/posts/2025-04-16-launch [2]: https://openssf.org/blog/2025/04/23/vulnerability-enumeration-conundrum-an-open-source-perspective-on-cve-and-cwe/ [3]: https://euvd.enisa.europa.eu Cheers, -- Paul Barker
signature.asc
(application/pgp-signature, 252 B)
-----BEGIN PGP SIGNATURE----- iIcEABYKAC8WIQSzjPXf5Y1BDWhU2iCrY1Tsnbr0bgUCaQiuShEccGF1bEBwYmFy a2VyLmRldgAKCRCrY1Tsnbr0bmaxAPwPi4qFLU5eicNLLESjbSR7rKflLtY73p92 P3N2fotAbQEA8SS4LY3p5wpzNJIWMO5DK/3SDJNYKsAOGee6Ojo3qA4= =pW8A -----END PGP SIGNATURE-----