{"repo":"AppThreat/vulnerability-db","free":true,"listed":false,"github":"https://github.com/AppThreat/vulnerability-db","clone":"git clone https://github.com/AppThreat/vulnerability-db.git","description":"Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.","language":"Python","stars":145,"topics":["vulnerability-detection","cve","vulnerability-database","nvd","cli","sca","advisories","database","purl","vers"],"license":"MIT","category":"databases-storage","readme_excerpt":"Introduction This repo is a vulnerability database and package search for sources such as AppThreat vuln-list, OSV, NVD, and GitHub. Vulnerability data are downloaded from the sources and stored in a sqlite based storage with indexes to allow offline access and efficient searches. Why vulnerability db? A good vulnerability database must have the following properties: - Accuracy - Easy to download, integrate, and use - Performance Multiple upstream sources are used by vdb to improve accuracy and reduce false negatives. SQLite database containing data in CVE 5.2 schema format is precompiled and distributed as files via ghcr to simplify download. With automatic purl prefix generation even for git repos, searches on the database can be performed with purl, cpe, or even http git url string. Every row in the database uses an open specification such as CVE 5.2 or Package URL (purl and vers) thus preventing the possibility of vendor lock-in. Vulnerability Data sources - Linux vuln-list (Forked from AquaSecurity) - OSV (1) - NVD - GitHub 1 - We exclude Linux and oss-fuzz feeds by default. Set the environment variable OSV INCLUDE FUZZ=true to include them. 2 - Malware feeds are included by default, thus increasing the db size slightly. Set the environment variable OSV EXCLUDE MALWARE=true to exclude them. Linux distros - AlmaLinux - Debian - Alpine - Amazon Linux - Arch Linux - RHEL/CentOS - Rocky Linux - Ubuntu - OpenSUSE - Photon - Chainguard - Wolfi OS Installation To install vdb wi","default_branch":null,"files":null,"tree":[],"storefront":"/r/AppThreat","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/AppThreat/vulnerability-db/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}