We are generally using the OSV format, the CVE format is to limiting, although some of the problems have been fixed in CVE v5 it's not really a good fit for us. Long term we may end up using STIX or some SBOM format depending on exactly what we're doing.
------------------------------
Kurt Seifried
Chief Blockchain Officer and Director of Special Projects
Cloud Security Alliance
[email protected]------------------------------
Original Message:
Sent: Nov 14, 2024 10:44:52 AM
From: John Wang
Subject: What data format do you use for sharing vulnerability data?
I'm looking at OpenVEX and the NVD CVE API formats. Are there other formats to consider and what are the pro and cons of each?
------------------------------
John Wang
VP Product Management
Saviynt
------------------------------