This should run at midnight every day (CET). So at most 23 hours of stale status for OSV.
Which actually sounds very dramatic. I can up the frequency to every 3 or 6 hours too if that is preferred.
Upstream -> downstream is usually right away as a build appears for an advisory we can match.
I haven't worked on the errata system in a while either but will take up some work around EOL of OVAL v2
if someone else doesn't pick it up.
For the CSAFv2 work we can integrate the OSV delivery into the system to make it "real time". We also
expect higher precision for security advisories with that move (better matching).
Let me know the preferred frequency for now and I'll set it to that.
Mustafa