Company · LegalBrowse
CompanyLegal
Data sources
sbomtriage builds on public vulnerability data that other people collect and publish. This page credits them and notes the licence each one is published under.
Advisories: OSV.dev
Advisory data comes from OSV.dev, which brings together advisories from many sources. Each source keeps its own licence. Among them:
- GitHub Advisory Database, licensed under CC BY 4.0.
- PyPI Advisory Database (PyPA), licensed under CC BY 4.0.
- Go Vulnerability Database, licensed under CC BY 4.0.
Advisories from other sources are under their own licences, listed on the OSV.dev data sources page. Reports show the advisory’s summary, which may be shortened to fit the page.
Known exploitation: CISA KEV
Whether a vulnerability is known to be exploited comes from the CISA Known Exploited Vulnerabilities catalog, published under CC0 1.0.
Exploit likelihood: FIRST EPSS
Exploit prediction scores come from the Exploit Prediction Scoring System (EPSS) by FIRST, the Forum of Incident Response and Security Teams. See https://www.first.org/epss.
Debian source packages
For Debian packages, the source package each one was built from is looked up in the Debian snapshot archive, because Debian files its advisories under source package names.
Trademarks
See also how the ranking is decided and all legal pages.