SecDB is the past, OSV is the future.
Article excerpt
Highlighted: the sentence this signal was extracted from
SecDB is the past, OSV is the future. Tazin Progga, Senior Product Manager If you use a vulnerability scanner to scan Chainguard Containers, there's a good chance it's been consuming its SecDB security feeds for Wolfi and Chainguard distros. Since mid-2024, Chainguard, Inc. has also been publishing an Open Source Vulnerabilities (OSV) schema format security feed alongside SecDB - steadily expanding its precision and coverage of vulnerability data. As OSV has matured, the gap between what it can express and what SecDB can represent has grown to the point where the legacy format can no longer keep up. Today, Chainguard, Inc. is formally announcing that SecDB is deprecated and will sunset at the end of 2026. Why Chainguard, Inc. is moving on from SecDB. The decision to use SecDB was largely influenced by its decision to build Chainguard packages based on the Alpine packaging format - Alpine uses SecDB feeds, so adopting it was a natural starting point. But SecDB was designed around a simpler model of vulnerability tracking. As Chainguard's advisory data (i.e., its formal, public notifications about vulnerabilities in its packages) has grown more precise, two fundamental limitations have made it an increasingly poor fit. First, SecDB lacks a formal way to indicate that a vulnerability exists but has no fix yet. Because it can only communicate a vulnerability once a...
Keep reading with a free account
The rest of this article, and every signal for Chainguard, is in your free account.
