Sign inSign up

validoolorg/open-vulnerability-data-mirror

By validoolorg

•Updated 14 days ago

Failure-safe NVD mirror by valitool GmbH, based on jeremylong/open-vulnerability-cli.

Image
Security
Developer tools
Databases & storage
0

647

validoolorg/open-vulnerability-data-mirror repository overview

⁠Open Vulnerability Data Mirror – valitool fork

This image is a valitool-maintained fork of the Open Vulnerability Data Mirror provided by the open-vulnerability-cli project.

This image is not an official image of the upstream project.

⁠Purpose of this fork

The fork provides failure-safe publication of NVD mirror files. A previously published mirror remains available while a new update is downloaded, generated, and validated.

Changed files are published only after the complete update has succeeded. A failed download, validation, replacement, or concurrent update therefore does not remove the last successfully published yearly files.

⁠Additional reliability features

  • transactional update in a staging directory
  • validation before publication
  • atomic replacement of changed mirror files
  • preservation of the previous mirror after update failures
  • validation of every yearly GZIP file from 2002 through the current year
  • separate validation of the modified feed
  • non-destructive handling of missing or corrupt files
  • protection against concurrent mirror updates
  • recovery from stale process locks
  • atomic writing of metadata, cache properties, and annual CVE counts
  • no logging of any part of the NVD API key

⁠Compatibility

The public URLs, filenames, volume path, and principal environment variables remain compatible with the upstream image.

The mirror is served from:

/usr/local/apache2/htdocs

⁠Usage

docker run \
  --name open-vulnerability-data-mirror \
  --restart unless-stopped \
  -e NVD_API_KEY=YOUR_API_KEY \
  -p 8080:80 \
  -v vulnerability-data:/usr/local/apache2/htdocs \
  validoolorg/open-vulnerability-data-mirror:9.0.6-valitool.1

The mirror is then available at:

http://localhost:8080/

For production use, pin a specific version instead of relying on latest.

⁠Image variants

The image is published for:

  • linux/amd64
  • linux/arm64

⁠Versioning

Tags use the following scheme:

<upstream-version>-valitool.<revision>

Example:

9.0.6-valitool.1

The upstream version identifies the corresponding open-vulnerability-cli release. The valitool revision identifies changes to this maintained fork.

⁠Attribution

This image is derived from the work of Jeremy Long and the contributors to the Open Vulnerability Project. The reliability changes described above are maintained separately by valitool GmbH.

Tag summary

Content type

Image

Digest

sha256:70de03a06…

Size

267.9 MB

Last updated

14 days ago

docker pull validoolorg/open-vulnerability-data-mirror