Why developers need a supplemental source to NVD vulnerability data

The NVD is a good source for open source vulnerability data. But with an average 27-day reporting delay, it shouldn’t be your only source of information. Public sources, such as the National Vulnerability Database ( NVD ), are a good first step for information on publicly disclosed vulnerabilities in open source software.