_This is slightly premature of me to be putting into circulation, but I want an issue ID to add to material I'm creating for collecting feedback..._ Related: #162 and #163 # Proposed Story <details> <summary>Proposed Story</summary> - OSV is “the (better) CVE, for Open Source Software vulnerabilities” - Remove the globally unique identifier gap - Draw clear lines as to how it meets the intent of existing compliance regimes - Free from single-points-of-failure - OSV Schema is an OpenSSF project - Home databases are fully federated - OSV.dev - Has alternatives - Is sufficiently de-risked </details> # The Opportunity for OSV to fill this gap <details> <summary>The Opportunity for OSV to fill this gap</summary> - OSV already exists - Highly machine-readable - Today, 20+ fully-federated home databases, aggregated by [OSV.dev](https://GitHub.com/Google/OSV.dev) (Google-sponsored) - Reference tooling exists ([OSV-Scanner](https://GitHub.com/Google/osv-scanner), Google-sponsored) - Open source-scoped CVE Program CNAs parallel-publish in OSV and CVE - Requires reducing friction around OSV home database standup - Requires reducing friction around home database record management - Actively learn from CVE Program’s 25 year history - Scaling challenges and operational bottlenecks - Data quality guardrails - https://osv.dev/blog/posts/announcing-data-quality-initiatives/ </details>