Skip to content

Conversation

@maennchen
Copy link
Contributor

@maennchen maennchen commented Oct 16, 2025

We're providing information in the OSV format for all the Hex.pm vulnerabilities for which our CNA assigns.

Our CNA scope includes all Hex.pm packages, unless covered by the scope of another CNA.

Since we're primarily a CNA ond this effort is to raise compatibility with the information we provide in our CVE entries, We'll be naming them EEF-<CVE ID>.

OSV REST Link: https://cna.erlef.org/osv/all.json
OSV Detail URL: https://cna.erlef.org/osv/<ID>.json
List of Vulnerabilities: https://cna.erlef.org/cves/
Our stuff on GH: https://github.com/erlef-cna

@maennchen maennchen mentioned this pull request Oct 16, 2025
6 tasks
Signed-off-by: Jonatan Männchen <jonatan@maennchen.ch>
@another-rex
Copy link
Collaborator

Looks great! Thank you.

@another-rex another-rex merged commit 3d1fb54 into ossf:main Oct 27, 2025
7 checks passed
@maennchen maennchen deleted the jm/eef_cna branch October 27, 2025 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants