Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature: VDB update frequency information #280

Open
johennin opened this issue Mar 21, 2024 · 2 comments
Open

Feature: VDB update frequency information #280

johennin opened this issue Mar 21, 2024 · 2 comments
Labels
enhancement New feature or request

Comments

@johennin
Copy link

Request Description

Hello! I'm just curious about how often the vulnerability database updates, I've looked through the help CLI command, OWASP page, git page and even the source code but can't seem to find any information regarding the update frequency of the VDB or how often it updates.

My initial guess is that the database is updated dynamically every time a new vulnerability is released but that's only a guess.

This is also a suggestion/request to add the database update frequency somewhere because many other SBOM scanners such as Trivy and Grype mentions it for transparency and reliability reasons.

(If it stands somewhere and I missed it I apologize in advance)

Thank you!

Additional Information

No response

@johennin johennin added the enhancement New feature or request label Mar 21, 2024
@prabhu
Copy link
Member

prabhu commented Mar 21, 2024

@johennin, the update frequency is 6 hours as mentioned here.

https://github.com/AppThreat/vdb/blob/main/.github/workflows/build.yml#L5

Please feel free to fork the vdb repo to customize the update frequency. You can pass the custom download URL using the environment variables here or simply download the file to the VDB_HOME directory before invoking depscan.

@johennin
Copy link
Author

Alright, thank you for the quick and precise response!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants