Data Feeds
To effectively search for threats in open source components, CodeScoring integrates data from more than 20 knowledge sources (feeds). Records from all sources are deduplicated and combined under universal identifiers in the system.
Threat knowledge sources complement the unified CodeScoring Index database with information about published components, including two proprietary feeds: CodeScoring Cloned Vulnerabilities and CodeScoring Protestware Feed.
CodeScoring Cloned Vulnerabilities (CSCV) links Maven packages containing reused fragments of vulnerable code to the original CVE and library. This makes it possible to detect the vulnerability in other components even when public sources identify only the original library as affected.
This section contains a detailed description of individual feeds and the process of working with them.
Below is a table with the data sources and their update frequency.
