5 ms·
Quite so. I would love to see an open sourced CVE database. It is for the public, it should be by the public.
by hanlonsrazor 1y ago
Quite so. I would love to see an open sourced CVE database. It is for the public, it should be by the public.
- c7b 1y agoWhat do you mean? A government service is a public service, by any conventional use of the term. Public/private is orthogonal to open source.
- aerostable_slug 1y agoCommunity-maintained might be a better phrasing. There's no particular reason a vulnerability database needs to be government-sponsored, and some compelling reasons why it shouldn't be "owned" by one government or another (one being guaranteed continuity even during seasons of change).