-
Notifications
You must be signed in to change notification settings - Fork 325
Root Datasource #3937
Copy link
Copy link
Closed
Labels
autoclosedClosed by automationClosed by automationdatasourceRequests for new data sourcesRequests for new data sourcesstaleThe issue or PR is stale and pending automated closureThe issue or PR is stale and pending automated closure
Metadata
Metadata
Assignees
Labels
autoclosedClosed by automationClosed by automationdatasourceRequests for new data sourcesRequests for new data sourcesstaleThe issue or PR is stale and pending automated closureThe issue or PR is stale and pending automated closure
Type
Fields
Give feedbackNo fields configured for issues without a type.
Hi 👋
We are Root and we are creating images with zero vulnerabilities. Unlike other datasources, we fix the vulnerabilities using the original operating system. That is, we create our Root version of packages for Debian, Ubuntu, Alpine, Rocky, etc.
In addition, we are also creating patches for application level vulnerabilities for all the major languages: Go, Python, JS, etc.
Looking at other implementations, I see this is not standard as most (if not all) feeds address only one ecosystem or one package manager, whereas we are multi-ecosystem + multi-package managers
I would appreciate your guidance on the best way going forward of adding our feeds to osv:
I hope our use case is clear and will be more than happy to explain in more detail if needed