Vulnerability-Lookup 5.0.0 released (www.vulnerability-lookup.org)
from cedric@lemmy.ml to security@lemmy.ml on 29 May 11:34
https://lemmy.ml/post/48001580

We are thrilled to announce the release of Vulnerability-Lookup 5.0.0!

This major release centers on a new CNA-compliant API for managing the vulnerabilities of your local source, together with deep Vulnogram integration, a continued UI refresh, and a long list of stability and correctness fixes.

A special thank you to Niclas Dauster for the substantial contribution behind the new CNA-interoperable API (#398).

What’s New

CNA- and GNA-Compatible Vulnerability Management

Vulnerabilities in your local instance can now be managed in a CNA-interoperable way through a dedicated API.

It streamlines Coordinated Vulnerability Disclosure (CVD) through a built-in Vulnogram integration compatible with both CVE 5.2 and GCVE-BCP-05, allowing CNAs and GNAs to publish advisories and synchronize with other instances regardless of the identifier format used.

The new API endpoint is partially interoperable with existing CNA endpoints from the CVE program, building on its solid foundation to enable a compatible and unified system for publishing vulnerability information. The API may be refined in upcoming releases based on feedback from adopters. We firmly believe that interoperable, reusable open-source components are key to preventing fragmentation in the vulnerability ecosystem.

We also welcome other vulnerability publication programs to extend this API to support their specific use cases or new models that could further improve automation in vulnerability handling.

Vulnogram integration

Vulnogram now drives ID reservation within vulnerability-lookup directly and vulnerability data management directly through the new CNA-interoperable API:

Configurable identifier allocation

You can now configure GCVE identifier allocation ranges for reservation. A bin script is also provided to migrate existing data to the new GNA ID format.

Website improvements

API

Changes

Fixes

It also addresses a number of other issues:

Migration Notes

A bin script is provided to migrate existing local-source data to the new GNA ID format.

Changelog

📂 For the full list of changes, check the GitHub release:
github.com/vulnerability-lookup/…/v5.0.0

🙏 A big thank you to all contributors and testers!

Feedback and Support

If you encounter any issues or have suggestions, feel free to open a ticket on our GitHub repository:
github.com/vulnerability-lookup/…/issues/
Your feedback is always appreciated!

Follow Us on Fediverse/Mastodon

You can follow us on Mastodon and get real-time information about security advisories:
social.circl.lu/@vulnerability_lookup/

#security

threaded - newest