It seems that in recent weeks, the summary more and more often fails to list software vendors in the first column… instead now showing most entries as “n/a – n/a”. This means a reader must scan through all the textual “Description” paragraphs to uncover which software products are involved for each entry (and none of these n/a entries are alphabetized by vendor). This is becoming an increasingly tedious task for those of us who check the list to see whether some of our software needs CVE-related security/update attention. It ought to be a simple matter for CISA to require vendor identification to be included in that first column field like it used to be. I wonder what changed in the data processing used to create the listing at CISA to cause this…