Hey fleet team, I notice https://nvd.nist.gov/vuln/data-feedsOn December 15th, 2023, the NVD plans to retire all legacy data feeds. Is fleet depending on the NVD data feeds for updated software CVE. If yes, any plans on using their APIs?
g
Grant Bilstad
10/31/2023, 4:52 PM
Greetings @Jian Zheng,
Thank you for bringing to our attention.
fleet's vulnerability processing is documented here-
https://fleetdm.com/docs/using-fleet/vulnerability-processing#performance
and currently leverages data feed.
There are a few things in the works for when NIST retires data feeds and API 1.0. We're currently vetting and researching solutions.