The Distributed Open-Source Vulnerability Ecosystem
For security practitioners and researchers, it provides a conceptual framework to understand and address inconsistencies in vulnerability scanning, but is primarily descriptive and incremental.
The paper identifies causes of inconsistent vulnerability scanner results across the open-source ecosystem, attributing them to heterogeneous sources, divergent identity/version models, temporal change, and context-dependent assessment.
Identifying known software vulnerabilities is a central task in software supply chain security management. Although publicly available vulnerability information is based on shared standards, different vulnerability scanners often report divergent results for identical software inventories. These differences do not arise solely from individual data sources or scanner implementations. They can emerge at several stages of the open-source vulnerability ecosystem. This paper presents a conceptual framework that describes vulnerability management as a distributed process of information exchange and transformation. It traces vulnerability information from its creation and standardization through enrichment to context-dependent interpretation. The analysis identifies heterogeneous information sources, divergent identity and version models, temporal change, and context-dependent assessment as major causes of inconsistent scanner findings. It then discusses the implications for interpreting analysis results, designing reproducible evaluation methods, and handling dynamic vulnerability knowledge in practice.