# open source vulnerabilities

Published articles for open source vulnerabilities.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## SecDB is the past, OSV is the future

DevFeed: [SecDB is the past, OSV is the future](<https://devfeed.tech/articles/secdb-is-the-past-osv-is-the-future-13218.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/secdb-is-the-past-osv-is-the-future>)

Published: 2026-04-09T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard packages](<https://devfeed.tech/topics/chainguard-packages.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [cves](<https://devfeed.tech/tags/cves.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [osv](<https://devfeed.tech/tags/osv.md>), [secdb](<https://devfeed.tech/tags/secdb.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard is deprecating its SecDB vulnerability feed and plans to sunset it at the end of 2026. The company is moving toward the OSV schema because it supports more precise vulnerability data, including unfixed vulnerabilities and component-level advisory details.

### Source excerpt

Chainguard is deprecating SecDB in favor of OSV, delivering more accurate, granular vulnerability data and better visibility for modern software supply chains.

## Prioritize with Snyk's Open Source Vulnerability Experience

DevFeed: [Prioritize with Snyk's Open Source Vulnerability Experience](<https://devfeed.tech/articles/prioritize-with-snyk-s-open-source-vulnerability-experience-8054.md>)

Original publisher: [Read original article](<https://snyk.io/blog/prioritize-with-snyks-open-source-vulnerability-experience/>)

Author: Ryan McMorrow

Published: 2025-08-20T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Library](<https://devfeed.tech/topics/library.md>), [Development](<https://devfeed.tech/topics/development.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cost](<https://devfeed.tech/tags/cost.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk introduces a new default vulnerability view that groups open source vulnerabilities by dependency and the versions that fix them. The view helps teams compare upgrades by their remediation impact and cost-benefit tradeoffs, making it easier to prioritize library updates and resolve more issues efficiently.

### Source excerpt

Discover Snyk's new default view, grouping vulnerabilities by library and fix versions to help you prioritize and remediate open source vulnerabilities more efficiently.

## The New Threat Landscape: AI-Native Apps and Agentic Workflows

DevFeed: [The New Threat Landscape: AI-Native Apps and Agentic Workflows](<https://devfeed.tech/articles/the-new-threat-landscape-ai-native-apps-and-agentic-workflows-8209.md>)

Original publisher: [Read original article](<https://snyk.io/blog/the-new-threat-landscape-ai-native-apps-and-agentic-workflows/>)

Author: Snyk Team

Published: 2025-06-17T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Security](<https://devfeed.tech/topics/security.md>), [Adversarial attacks](<https://devfeed.tech/topics/adversarial-attacks.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devops](<https://devfeed.tech/tags/devops.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [executive](<https://devfeed.tech/tags/executive.md>), [external](<https://devfeed.tech/tags/external.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

The article examines the expanding threat landscape around AI-native applications and agentic workflows. It discusses risks including data poisoning, prompt injection, open-source vulnerabilities, and identity gaps, and argues that traditional application security practices need stronger visibility and policy enforcement for AI systems.

### Source excerpt

As AI-native apps and agentic workflows expand the attack surface, new threats like prompt injection and data poisoning emerge. Learn why traditional AppSec falls short and how to secure your AI systems in this new threat landscape.

## Chainguard enhances security with OSV advisory feed

DevFeed: [Chainguard enhances security with OSV advisory feed](<https://devfeed.tech/articles/chainguard-enhances-security-with-osv-advisory-feed-12943.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-enhances-security-with-osv-advisory-feed>)

Published: 2024-07-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [data](<https://devfeed.tech/topics/data.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [google](<https://devfeed.tech/tags/google.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [osv](<https://devfeed.tech/tags/osv.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard is publishing its security advisory feed in the OSV format, improving the precision and usability of vulnerability information for open source maintainers and downstream consumers.

### Source excerpt

Explore Chainguard's new OSV advisory feed, delivering comprehensive and up-to-date vulnerability information to enhance your security posture.