docs: add NVD import method comparison#15
Merged
Conversation
Document the investigation of what the OSV NVD-CVE-OSV converter actually does: - CPE→Git repository resolution - Git commit range generation (primary enrichment) - No purl/ecosystem/package info added - 52-82% conversion success rate Recommend consolidating to NVD native only, since: - Complete CVE coverage (vs partial) - Full CPE configuration logic preserved - Delta update support - The OSV enrichment (Git commit ranges) serves a use case Mayu doesn't currently implement Includes Japanese translation (docs/nvd-import-comparison.ja.md)
kato83
force-pushed
the
docs/nvd-import-comparison
branch
from
July 24, 2026 15:30
85c01d3 to
95942ec
Compare
kato83
added a commit
that referenced
this pull request
Jul 25, 2026
docs: add NVD import method comparison
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add documentation comparing the two NVD import methods in Mayu:
mayu ingest --source nvd(OSV-converted from GCS bucket)mayu ingest --source nvd --native(direct NVD JSON Feed 2.0)Motivation
Users may be confused by the
--nativeflag on--source nvd. This document clarifies what each method provides and recommends a path forward.Key Findings
The OSV conversion tool is not a simple format conversion — it resolves CPE version ranges to Git commit hashes via tag analysis. However:
Recommendation
Consolidate to NVD native only (
--source nvdwithout needing--nativeflag). This simplifies the CLI without losing functionality.Changes
docs/nvd-import-comparison.md— detailed comparison documentREADME.md/README_ja.md— links to the new document in Data Sources section