We need to generate OSV records from historical and future CVE records in the NVD that we can determine to relate to Open Source Software. These records will be keyed by commit. A side-effect of this is we will start picking up vulnerabilities in C/C++ packages.