Hi!
This week in the OpenSSF Vulnerability Disclosures working group Crob shared the attached file about a new project being set up by the OpenSSF.
The target is to build on
OSV.DEV and extend it. Several members of the foundation has pledged serious funding for this project and the board
has approved the initial plans. At the core is this recommendation:
"Recommendation:
We propose expanding the existing Open Source Vulnerability database (OSV) ecosystem to extend the already existing global, federated vulnerability management system, anchored in open collaboration. This expanded system would build services, processes, and tooling to make it easy for projects, communities, and organizations to contribute data and participate actively across the federated network.
Potential path forward has been identified:
Create a neutral, non-profit Foundation that would oversee this initiative, operating under the umbrella of the Open Source Security Foundation (OpenSSF). This new Foundation would drive cross-ecosystem coordination, stewardship of the federated model, and development of shared services (such as contribution tooling, discovery APIs, and shared trust and validation mechanisms) as well as hosting such infrastructure.
We will be assembling a broad coalition of SMEs from across industry and OSS foundations/projects to help develop and implement this program.”
Many of the requirements produced by this group has been used as input for this work. The OpenSSF invites other foundation to join the work
to make sure this is beneficial for all.
In short:
* Set up a new foundation
* Build on the existing work in
OSV.DEV
* Google is willing to migrate the existing
OSV.DEV platform into this new project
* Add an workflow where projects can get support for handling their issues
* Make sure projects report once and issues will be forwarded to other vulnerability management systems
Nothing is carved in stone yet, so there will be room for discussions.
When I started the GVIP I focused on the long term solution. I still believe we need to continue that work
and spend time on moving GVIP forward.
This work is targeting the short term problems with the CVE program and the NVD. In addition, it will
be important in the light of worldwide regulations, right now with a focus on the EU CRA.
There will be an invitation to workgroup meetings for this project very soon.
As soon as it is sorted out, I will forward the meeting info to this mailing list.
Looking forward to your feedback!
/Olle