Skip to main content
ChainguardLaunch

SecDB is the past, OSV is the future.

What happened

Chainguard, Inc. launched Open Source Vulnerabilities schema format security feed on Jul 1st '24.

Source

chainguard.devApr 9, 2026

SecDB is the past, OSV is the future.

Article excerpt

Highlighted: the sentence this signal was extracted from

SecDB is the past, OSV is the future. Tazin Progga, Senior Product Manager If you use a vulnerability scanner to scan Chainguard Containers, there's a good chance it's been consuming its SecDB security feeds for Wolfi and Chainguard distros. Since mid-2024, Chainguard, Inc. has also been publishing an Open Source Vulnerabilities (OSV) schema format security feed alongside SecDB - steadily expanding its precision and coverage of vulnerability data. As OSV has matured, the gap between what it can express and what SecDB can represent has grown to the point where the legacy format can no longer keep up. Today, Chainguard, Inc. is formally announcing that SecDB is deprecated and will sunset at the end of 2026. Why Chainguard, Inc. is moving on from SecDB. The decision to use SecDB was largely influenced by its decision to build Chainguard packages based on the Alpine packaging format - Alpine uses SecDB feeds, so adopting it was a natural starting point. But SecDB was designed around a simpler model of vulnerability tracking. As Chainguard's advisory data (i.e., its formal, public notifications about vulnerabilities in its packages) has grown more precise, two fundamental limitations have made it an increasingly poor fit. First, SecDB lacks a formal way to indicate that a vulnerability exists but has no fix yet. Because it can only communicate a vulnerability once a...

Keep reading with a free account

The rest of this article, and every signal for Chainguard, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Takes effect
Jul 1, 2024

The full record

From the Signal API record

Details

Product
Open Source Vulnerabilities schema format security feed
Category
Launches

Topics and mentions

Product tags

  • security

Extraction

Confidence
48%
Detected
Apr 9, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Chainguard and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Chainguard this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/f8e4bc97-1794-4127-8193-ee8aed814bf6 returns this record as JSON. POST /v1/companies/enrich returns every signal for chainguard.dev.

{
  "signal_id": "f8e4bc97-1794-4127-8193-ee8aed814bf6",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-04-09T00:00:00+00:00",
  "company": {
    "name": "Chainguard",
    "domain": "chainguard.dev"
  },
  "data": {
    "url": "https://www.chainguard.dev/unchained/secdb-is-the-past-osv-is-the-future",
    "title": "SecDB is the past, OSV is the future.",
    "excerpt": "SecDB is the past, OSV is the future.\n\nTazin Progga, Senior Product Manager\n\nIf you use a vulnerability scanner to scan Chainguard Containers, there's a good chance it's been consuming its SecDB security feeds for Wolfi and Chainguard distros. Since mid-2024, Chainguard, Inc. has also been publishing an Open Source Vulnerabilities (OSV) schema format security feed alongside SecDB - steadily expanding its precision and coverage of vulnerability data. As OSV has matured, the gap between what it can express and what SecDB can represent has grown to the point where the legacy format can no longer keep up. Today, Chainguard, Inc. is formally announcing that SecDB is deprecated and will sunset at the end of 2026.\n\nWhy Chainguard, Inc. is moving on from SecDB.\n\nThe decision to use SecDB was largely influenced by its decision to build Chainguard packages based on the Alpine packaging format - Alpine uses SecDB feeds, so adopting it was a natural starting point. But SecDB was designed around a simpler model of vulnerability tracking. As Chainguard's advisory data (i.e., its formal, public notifications about vulnerabilities in its packages) has grown more precise, two fundamental limitations have made it an increasingly poor fit.\n\nFirst, SecDB lacks a formal way to indicate that a vulnerability exists but has no fix yet. Because it can only communicate a vulnerability once a...",
    "product": "Open Source Vulnerabilities schema format security feed",
    "summary": "Chainguard, Inc. launched Open Source Vulnerabilities schema format security feed on Jul 1st '24.",
    "category": "launches",
    "found_at": "2026-04-09T00:00:00Z",
    "planning": false,
    "image_url": "https://images.ctfassets.net/l47ir7rfykkn/gkUjTrkxbA4Mb6BqOgBgE/cb2c9a56d52d36bf884af2c0a9fc10cb/SecDB_is_the_past__OSV_is_the_future.png",
    "confidence": 0.4846,
    "product_data": {
      "full_text": "Open Source Vulnerabilities (OSV) schema format security feed",
      "fuzzy_match": true
    },
    "product_tags": [
      "security"
    ],
    "published_at": "2026-04-09T00:00:00Z",
    "effective_date": "2024-07-01",
    "article_sentence": "Since mid-2024, Chainguard, Inc. has also been publishing an Open Source Vulnerabilities (OSV) schema format security feed alongside SecDB - steadily expanding its precision and coverage of vulnerability data."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.