Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Echo OSV feed integration #3453

@orizerah

Description

@orizerah

Hi! Hoping to coordinate on a new vunnel provider that introduces Echo OSV advisories.

Our PR: anchore/vunnel#1174echo-osv, which ingests Echo's OSV feed (https://advisory.echohq.com/osv/all.zip) for the Echo:PyPi and Echo:npm language ecosystems. Echo ships patched builds of upstream PyPI/npm packages (e.g. pip at 25.2+echo.1 for CVE-2026-1703), so we mark records as advisories so grype routes them through the unaffected store — that way the patched build clears the upstream CVE instead of false-positiving on every Echo image.

We're in the same boat as the OSV PRs already listed in #3252 (CRAN #1043, BellSoft #924, openEuler #839):

A question:

Anything specific our records should include for #3252 to handle Echo:PyPi / Echo:npm cleanly via the unaffected store? Records carry PURLs (pkg:pypi/..., pkg:npm/...) so PURL-based detection should work, but want to confirm.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions