You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
But OSVDB doesn't allow commercial usage without agreement.
If the OSVDB is the basis of, or integrated with in any manner a commercially available product or service you MUST notify OSVDB by providing details on the usage and reach a licensing agreement prior to usage.
We already have some data sources for Ruby. We can remove those advisories so that Trivy can be used in commercials.
Overview
One of our data sources, ruby-advisory-db depends on advisories from OSVDB.
https://github.com/rubysec/ruby-advisory-db/blob/master/LICENSE.txt
But OSVDB doesn't allow commercial usage without agreement.
We already have some data sources for Ruby. We can remove those advisories so that Trivy can be used in commercials.
Implementation
Skip OSVDB here.
https://github.com/aquasecurity/trivy-db/blob/62aa4616130e5e27b1eb33bf65a2e6b44090fc43/pkg/vulnsrc/bundler/bundler.go
References
rubysec/ruby-advisory-db#487
The text was updated successfully, but these errors were encountered: