-
Notifications
You must be signed in to change notification settings - Fork 115
Ensure that distro advisories and aliasing work well together #249
Description
Raised @luhring in google/osv.dev#2374 and capturing here:
It looks like the aliases documentation line in question was updated in #193 — that was a great read. I share the concern expressed in that PR: There seems to be a "hole" in the OSV spec when it comes to distros' ability to participate. By moving to
related, we're missing out on the opportunity to have strong, automation-usable links to the same vulnerability as described by our advisories. It seems like there should be a new field that's similar toaliases, but for strong "asymmetric" references, to help OSV better support vulnerability workflows beyond language ecosystems and into the world of distros. I can open an issue to capture this, and hopefully we'll have a good dialog there about potential improvements to the spec.