GithubHelp home page GithubHelp logo

Comments (8)

TheFoxAtWork avatar TheFoxAtWork commented on July 20, 2024 2
  1. User wants to look up/add/correlate multiple identifiers for the same object (Snyk ID, v. CVE, v. other vendor ID)
  2. User wants to subscribe/unsubscribe from GSD notices on a particular keyword or component
  3. User wants to link articles/posts around breaches/exploits of a known vuln (potential auto updated from RSS filtering?) (mark links as useful not useful or dead)

from gsd-tools.

joshbressers avatar joshbressers commented on July 20, 2024 2

I think starting with a highly constrained scope is a good idea

from gsd-tools.

ThatOhGi avatar ThatOhGi commented on July 20, 2024 1

Hey everybody, I'm new to open source and dev, I've been looking for a project to support since October but nothing really jumped out at me until this one. Sorry if this isn't the place for an intro but I wanted to share my experience level and manage expectations. I'm excited about this project for two reasons, one it is still young enough I feel confident jumping in without being overwhelmed and secondly who doesn't love staying up-to-date with the most current CVEs!

I'm not sure what expertise I can lend to the project but I'm happy to help with documentation and yak shaving. If there is something specific to focus on I'm happy to dig in.

from gsd-tools.

joshbressers avatar joshbressers commented on July 20, 2024 1

Hi @ThatOhGi

Welcome aboard!

This isn't the best place to have a discussion. Can you subscribe to the mailing list and basically copy and paste your message there?
https://groups.google.com/a/groups.cloudsecurityalliance.org/g/gsd

I know it's scary to start a new post sometimes but I promise your mail will be most welcome!

from gsd-tools.

mathrock avatar mathrock commented on July 20, 2024

Since the success of the Global Security Database (GSD) is heavily based on getting user buy-in and contribution, users need to see how it can solve problems for which they don’t currently have solutions.

I think it should be clearer what current problems are initially in-scope to be solved by GSD, which from what I understand fall under the following two main categories:

  • Creating new identifiers for use-cases outside the current CVE/NVD scope
  • Crowdsourcing enrichment or corrections to existing vulnerability data
    • Correcting typos (Zabbix vs Zabbiz)
    • Correcting scoring/severity issues
    • Mapping vulnerability identifiers
      • GSD -> CVE -> Vendor identifiers like RHSA, USN, etc
      • GSD -> CVE -> Third-party vulnerability identifiers like GHSA, Snyk, VulnDB, etc
    • Additional crowdsourced vulnerability data enrichment:
      • Links to exploits, research, etc

This is not to suggest that I'm recommending limiting the scope, just focusing on some core use cases so that hopefully others will be encouraged to contribute and grow the community.

from gsd-tools.

joshbuker avatar joshbuker commented on July 20, 2024

Putting this link in the first place I looked: https://github.com/cloudsecurityalliance/gsd-database/blob/draft-docs/CONTRIBUTOR.md

Still working on fleshing this out in such a way that it's easy to follow and concise.

from gsd-tools.

joshbuker avatar joshbuker commented on July 20, 2024

It appears this can be done at the organization level: https://docs.github.com/en/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file#supported-file-types

from gsd-tools.

joshbuker avatar joshbuker commented on July 20, 2024

Ruby on Rails CONTRIBUTING.md example: https://github.com/rails/rails/blob/main/CONTRIBUTING.md

from gsd-tools.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.