更新: 103 个文件 - 2026-03-18 19:24:37
这个提交包含在:
@@ -94,19 +94,24 @@ systems:
|
||||
tier: history-full
|
||||
advisory_modes: [core, plugin]
|
||||
official_sources:
|
||||
- name: WordPress Security News
|
||||
kind: html-links
|
||||
url: https://wordpress.org/news/category/security/
|
||||
- name: WordPress Security News RSS
|
||||
kind: rss-feed
|
||||
url: https://wordpress.org/news/category/security/feed/
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
keywords: [wordpress, security, release]
|
||||
max_items: 40
|
||||
request_policy:
|
||||
user_agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
|
||||
- name: NVD WordPress
|
||||
kind: nvd-search
|
||||
keyword: WordPress
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 50
|
||||
status: retired
|
||||
retired_reason: WordPress official RSS plus ecosystem plugin intelligence cover active collection with lower cold-start latency and lower public-search dependence than NVD.
|
||||
replacement_sources: [WordPress Security News RSS, Wordfence Vulnerability Database, WPScan Vulnerability Database]
|
||||
ecosystem_sources:
|
||||
- name: Wordfence Vulnerability Database
|
||||
kind: html-links
|
||||
@@ -166,6 +171,9 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 50
|
||||
status: retired
|
||||
retired_reason: OSV Drupal + Drupal official RSS now cover machine-readable collection with lower cold-start latency than NVD public search.
|
||||
replacement_sources: [Drupal Security Advisories RSS, OSV Drupal]
|
||||
ecosystem_sources:
|
||||
- name: Drupal Security Advisories Site
|
||||
kind: html-links
|
||||
@@ -186,8 +194,13 @@ systems:
|
||||
retired_reason: Unauthenticated GHSA API requests are rate-limited in daily monitoring; RSS and NVD remain active replacements.
|
||||
replacement_sources: [Drupal Security Advisories RSS, NVD Drupal]
|
||||
research_sources: []
|
||||
ecosystem_sources:
|
||||
- name: OSV Drupal
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
package_names:
|
||||
- ecosystem: composer
|
||||
- ecosystem: Packagist
|
||||
name: drupal/core
|
||||
cpe_keys: ["drupal:drupal"]
|
||||
ghsa_keywords: [drupal, drupal core]
|
||||
@@ -217,9 +230,18 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 50
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV Joomla CMS replaces NVD for machine-readable collection without public NVD throttling.
|
||||
replacement_sources: [Joomla Security Centre, OSV Joomla]
|
||||
ecosystem_sources:
|
||||
- name: OSV Joomla
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names: []
|
||||
package_names:
|
||||
- ecosystem: Packagist
|
||||
name: joomla/joomla-cms
|
||||
cpe_keys: ["joomla:joomla!"]
|
||||
ghsa_keywords: [joomla]
|
||||
kev_keywords: [joomla]
|
||||
@@ -248,7 +270,14 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV Ghost replaces NVD for machine-readable collection and keeps npm package alignment.
|
||||
replacement_sources: [Ghost GitHub Advisories, OSV Ghost]
|
||||
ecosystem_sources:
|
||||
- name: OSV Ghost
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: npm
|
||||
@@ -355,9 +384,18 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: MediaWiki announce RSS plus OSV MediaWiki now replace NVD for lower-latency machine-readable collection.
|
||||
replacement_sources: [MediaWiki Announce RSS, OSV MediaWiki]
|
||||
ecosystem_sources:
|
||||
- name: OSV MediaWiki
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names: []
|
||||
package_names:
|
||||
- ecosystem: Packagist
|
||||
name: mediawiki/core
|
||||
cpe_keys: ["mediawiki:mediawiki"]
|
||||
ghsa_keywords: [mediawiki]
|
||||
kev_keywords: [mediawiki]
|
||||
@@ -394,9 +432,18 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV Moodle replaces NVD for machine-readable collection while official Moodle sources remain for cross-checking.
|
||||
replacement_sources: [OSV Moodle]
|
||||
ecosystem_sources:
|
||||
- name: OSV Moodle
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names: []
|
||||
package_names:
|
||||
- ecosystem: Packagist
|
||||
name: moodle/moodle
|
||||
cpe_keys: ["moodle:moodle"]
|
||||
ghsa_keywords: [moodle]
|
||||
kev_keywords: [moodle]
|
||||
@@ -592,10 +639,17 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV OpenMage replaces NVD for machine-readable composer-aligned collection.
|
||||
replacement_sources: [OpenMage GitHub Advisories, OSV OpenMage]
|
||||
ecosystem_sources:
|
||||
- name: OSV OpenMage
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: composer
|
||||
- ecosystem: Packagist
|
||||
name: openmage/magento-lts
|
||||
cpe_keys: []
|
||||
ghsa_keywords: [openmage, mage-os]
|
||||
@@ -631,7 +685,14 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV WooCommerce replaces NVD for machine-readable collection while official and ecosystem advisory pages remain active.
|
||||
replacement_sources: [Woo Developer Advisories, GitHub WooCommerce Advisories, OSV WooCommerce]
|
||||
ecosystem_sources:
|
||||
- name: OSV WooCommerce
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
- name: Patchstack Database
|
||||
kind: html-links
|
||||
url: https://patchstack.com/database/
|
||||
@@ -650,7 +711,7 @@ systems:
|
||||
package_names:
|
||||
- ecosystem: npm
|
||||
name: "@woocommerce/blocks"
|
||||
- ecosystem: composer
|
||||
- ecosystem: Packagist
|
||||
name: woocommerce/woocommerce
|
||||
cpe_keys: []
|
||||
ghsa_keywords: [woocommerce]
|
||||
@@ -687,7 +748,14 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV PrestaShop replaces NVD for machine-readable collection while official and ecosystem advisories remain active.
|
||||
replacement_sources: [PrestaShop Security Page, GitHub PrestaShop Advisories, OSV PrestaShop]
|
||||
ecosystem_sources:
|
||||
- name: OSV PrestaShop
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
- name: Friends Of Presta Security
|
||||
kind: html-links
|
||||
url: https://security.friendsofpresta.org/
|
||||
@@ -697,7 +765,7 @@ systems:
|
||||
max_items: 50
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: composer
|
||||
- ecosystem: Packagist
|
||||
name: prestashop/prestashop
|
||||
cpe_keys: ["prestashop:prestashop"]
|
||||
ghsa_keywords: [prestashop]
|
||||
@@ -727,10 +795,17 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV Shopware replaces NVD for machine-readable collection with lower cold-start overhead.
|
||||
replacement_sources: [Shopware Security Advisories, OSV Shopware]
|
||||
ecosystem_sources:
|
||||
- name: OSV Shopware
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: composer
|
||||
- ecosystem: Packagist
|
||||
name: shopware/platform
|
||||
cpe_keys: []
|
||||
ghsa_keywords: [shopware]
|
||||
@@ -759,10 +834,17 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 50
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV OpenCart replaces NVD for machine-readable collection while official release source remains active.
|
||||
replacement_sources: [OpenCart Releases, OSV OpenCart]
|
||||
ecosystem_sources:
|
||||
- name: OSV OpenCart
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: composer
|
||||
- ecosystem: Packagist
|
||||
name: opencart/opencart
|
||||
cpe_keys: ["opencart:opencart"]
|
||||
ghsa_keywords: [opencart]
|
||||
@@ -791,10 +873,17 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV Saleor replaces NVD for machine-readable collection and aligns with the published PyPI package.
|
||||
replacement_sources: [GitHub Saleor Advisories, OSV Saleor]
|
||||
ecosystem_sources:
|
||||
- name: OSV Saleor
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: pypi
|
||||
- ecosystem: PyPI
|
||||
name: saleor
|
||||
cpe_keys: []
|
||||
ghsa_keywords: [saleor]
|
||||
@@ -1157,6 +1246,9 @@ systems:
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV Express replaces NVD public search for lower-latency machine-readable collection.
|
||||
replacement_sources: [OSV Express]
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: npm
|
||||
@@ -1195,6 +1287,9 @@ systems:
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV NestJS replaces NVD public search for lower-latency machine-readable collection.
|
||||
replacement_sources: [OSV NestJS]
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: npm
|
||||
@@ -1359,6 +1454,9 @@ systems:
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV Undici replaces NVD public search for lower-latency machine-readable collection.
|
||||
replacement_sources: [OSV Undici]
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: npm
|
||||
@@ -1397,6 +1495,9 @@ systems:
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV webpack replaces NVD public search for lower-latency machine-readable collection.
|
||||
replacement_sources: [OSV webpack]
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: npm
|
||||
@@ -1435,6 +1536,9 @@ systems:
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV esbuild replaces NVD public search for lower-latency machine-readable collection.
|
||||
replacement_sources: [OSV esbuild]
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: npm
|
||||
@@ -1775,6 +1879,9 @@ systems:
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: OSV Rails replaces NVD public search for lower-latency machine-readable collection.
|
||||
replacement_sources: [OSV Rails]
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: RubyGems
|
||||
@@ -2083,7 +2190,14 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: OSV phpMyAdmin replaces NVD for machine-readable collection while the official security page remains active.
|
||||
replacement_sources: [phpMyAdmin Security Page, OSV phpMyAdmin]
|
||||
ecosystem_sources:
|
||||
- name: OSV phpMyAdmin
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: Packagist
|
||||
@@ -2299,6 +2413,9 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
status: retired
|
||||
retired_reason: Mattermost official JSON feed plus OSV Mattermost replace NVD for lower-latency machine-readable collection.
|
||||
replacement_sources: [Mattermost Security Updates JSON, OSV Mattermost]
|
||||
- name: Mattermost Security Updates JSON
|
||||
kind: json-feed
|
||||
url: https://securityupdates.mattermost.com/security_updates.json
|
||||
@@ -2307,9 +2424,15 @@ systems:
|
||||
max_items: 600
|
||||
request_policy:
|
||||
accept: application/json
|
||||
ecosystem_sources: []
|
||||
ecosystem_sources:
|
||||
- name: OSV Mattermost
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names: []
|
||||
package_names:
|
||||
- ecosystem: Go
|
||||
name: github.com/mattermost/mattermost-server
|
||||
cpe_keys: ["mattermost:mattermost"]
|
||||
ghsa_keywords: [mattermost]
|
||||
kev_keywords: [mattermost]
|
||||
@@ -2337,7 +2460,14 @@ systems:
|
||||
confidence: official
|
||||
advisory_mode: core
|
||||
results_per_page: 40
|
||||
ecosystem_sources: []
|
||||
status: retired
|
||||
retired_reason: Official Redmine advisories page remains active and NVD public search is retired to reduce cold-start latency.
|
||||
replacement_sources: [Redmine Security Advisories]
|
||||
ecosystem_sources:
|
||||
- name: OSV Redmine
|
||||
kind: osv-batch
|
||||
confidence: ecosystem-authority
|
||||
advisory_mode: core
|
||||
research_sources: []
|
||||
package_names:
|
||||
- ecosystem: RubyGems
|
||||
|
||||
在新工单中引用
屏蔽一个用户