top | item 43975247

(no title)

hanlonsrazor | 9 months ago

Quite so. I would love to see an open sourced CVE database. It is for the public, it should be by the public.

discuss

order

c7b|9 months ago

What do you mean? A government service is a public service, by any conventional use of the term. Public/private is orthogonal to open source.

aerostable_slug|9 months ago

Community-maintained might be a better phrasing.

There's no particular reason a vulnerability database needs to be government-sponsored, and some compelling reasons why it shouldn't be "owned" by one government or another (one being guaranteed continuity even during seasons of change).