Proprietaries sources of information
What approach do we take regarding proprietaries sources of information such as https://vfeed.io/ ? In one way they may provide valuable information for the platform, on the other way they diminish the reproducibility of the data for those who cannot finance a subscription.
Yes that's tricky because for instance the CII census used the Blackduck data and had to include an IP waiver in their repo. vFeed has more open-friendly licensing terms (Community / Non Commercial Usage / Integrated with Open Source Software / Integrated within Free Web Services / Used in Public Research and Surveys / No credit card / $0 Forever). But the problem remain that it's not published with an open license. What are the terms on CVE items and other CVE sources? Are there some with an explicit open license?
Moved from project/architecture#36Toggle commit list