Package Metadata Database

  • Tier: Ultimate
  • Offering: GitLab Self-Managed, GitLab Dedicated

The Package Metadata Database (PMDB) is a collection of license and security advisory data for open source packages, maintained by GitLab. GitLab synchronizes it into the database of your instance, where the following features read it:

The Package Metadata Database is licensed under the EE License.

Datasets

The Package Metadata Database holds four datasets:

DatasetContentsUsed by
LicensesLicense data for package versions.License scanning
AdvisoriesSecurity advisories for package versions.Dependency scanning, continuous vulnerability scanning, and container scanning for registry
CVE enrichmentThe EPSS score and KEV status of vulnerabilities.Vulnerability risk assessment data
Malware advisoriesKnown malicious packages found in package registries.GitLab malware advisories

By default, GitLab synchronizes data for all package registry types. To synchronize less data, clear the package registry types that you do not use in the admin settings.

Data format versions

Each dataset is published in one of two data format versions, v2 or v3. These are versions of the data format, not GitLab versions.

Format versionDatasetsDistributed from
v2Licenses for GitLab 19.3 and earlier, advisories, and CVE enrichment.Public Google Cloud Storage buckets, readable without credentials.
v3Licenses for GitLab 19.4 and later, and malware advisories.The Package Metadata Database distribution service, an authenticated GitLab service.

v3 license data carries Software Package Data Exchange (SPDX) license expressions instead of single license identifiers. For example, MIT OR Apache-2.0.

You do not choose the format version. Your GitLab version determines which one it reads:

GitLab versionLicensesAdvisoriesCVE enrichmentMalware advisories
19.2 and earlierv2v2v2Not available
19.3v2v2v2v3
19.4 and laterv3v2v2v3

Feature flags control the v3 license data and the malware advisories, and both are enabled by default. Malware advisories are in beta.

Synchronization

Cron jobs in Sidekiq synchronize each dataset into the database of your instance. Each run resumes from the checkpoint that the previous run recorded, so it imports only data that is newer than what the instance already holds.

Instances with internet access

An instance with internet access downloads v2 data from the public buckets and v3 data from the distribution service. To download v2 data, the instance needs outbound network access to storage.googleapis.com.

Offline instances

An offline instance cannot download the data itself. Instead, you download it on a machine with internet access and copy it into the vendor/package_metadata directory of the offline instance. Downloading v3 data requires an offline license.

When the directory for a dataset exists under vendor/package_metadata, GitLab reads that directory instead of downloading the data. There is no fallback to the network, so a directory that holds stale data serves stale data and reports no error.

For the download procedures and feature flag details for each dataset, see Package Metadata Database for offline instances.