Repository navigation
Support PURL as identifier #173
Description
Activity
Seconded. Had I known that Purl would take off I would have added it to the original CVE JSON specification I wrote.
Reacted by Steve Springett, Joseph Young, Mark Symons, Philippe Ombredanne, Chris Hibbard, Vijaya Sai Prasanth Kommini, Topaz Turkenitz, Nemo and Patrick SchmittThirded. Thanks, Steve, for your excellent writeup at OWASP New Recommendations to Improve The NVD.
I'm excited about the feature to query the NVD directly using the native package coordinates or purl of the software and receive accurate vulnerability information.Reacted by infojg9, WSINTRA, Mark Symons and Chris HibbardAs the original purl author I support this of course! and I am available to help as needed.
Reacted by TomalrichReacted by Ayan Sinha Mahapatra, Pablo Johnson and Jonatan MännchenThe schema currently does indeed support PURLs. The work pending in 5.1 is to allow versionType field for non-range versions (so one can say versionType="PURL"
What may be useful:
- Code to auto generate PURLs based on individual fields in the affected structure
- regex to validate PURLs.
You can currently (CVE JSON v5.0) supply them in the list of versions eg.,
"affected": [ { "collectionURL": "https://rubygems.org", "packageName": "ruby-advisory-db-check", "versions": [ { "status": "affected", "version": "pkg:gem/ruby-advisory-db-check@0.12.4" }, { "status": "affected", "version": "0.12.4" } ], "defaultStatus": "unaffected" } ],Reacted by Philippe OmbredanneFor the record, we have just released our entire CPE <-> PURL dataset here:
Reacted by Justin Hutchings, infojg9, Julian Coccia and mulder999@chandanbn It sounds like your suggestion to address purls is simply to add an extra version to the "affected" list pending the release of the CVE JSON 5.1. Is there any work in process on your other ideas of
- Code to auto generate PURLs based on individual fields in the affected structure
- Regex to validate PURLs
Also, any idea when CVE JSON 5.1 will be released?
impatiently awaiting CVE 5.1 for this. This will go a long way to solve the industry package Naming Problem.
Reacted by Justin Hutchingswill be addressed via #201
Hello, is there a way to track the progress of NVD adopting CVE JSON 5.1 and supporting queries with pURL ?
Thanks!Reacted by Jean-Baptiste Maillet and Pablo JohnsonAny update on this?
Reacted by Jean-Baptiste Maillet and Pablo JohnsonHi, I just looked at the CVE Record format here:
https://github.com/CVEProject/cve-schema/blob/main/schema/CVE_Record_Format.json... and there is STILL no reference to pURLs. Why isn't that in there yet? I thought purls were in the interchange format, but they appear to still be lacking.
Discussion has kicked off again that the current solution is insufficent.
Reacted by Seth Larson, Julian Coccia and Pablo Johnson- addedsection:affected_productSchema location is affected or productSchema location is affected or productNeeds DiscussionDiscuss in a future QWG meeting or on mailing listDiscuss in a future QWG meeting or on mailing list
on Jan 17, 2025 Excellent, thanks a lot fot the issue and thanks for having pointed it to me from
Added support for PURL identifiers in 5.2.0 (https://github.com/CVEProject/cve-schema/releases/tag/v5.2.0)
Reacted by SALESReacted by SALESReacted by SALES
Please add PURL as a unique identifier to the schema as there is currently no way to identify software component vulnerabilities without a PURL lookup. https://github.com/package-url/purl-spec