Why grype/anchore use ubuntu-cve-tracker (launchpad) as feed to detect Ubuntu CVE?
Ubuntu publishes OVAL feed for automating the detection of CVEs. I also notice there is ubuntu-cve-tracker (https://launchpad.net/ubuntu-cve-tracker) and grype/anchore uses that as a source of CVE feed.
Why is the Ubuntu OVAL feed itself n… Continue reading Why grype/anchore use ubuntu-cve-tracker (launchpad) as feed to detect Ubuntu CVE?