> 1. What would your expectations be towards a software vendor in terms of what issues to "fix"?
This is difficult to answer, as it really depends on the customer. I work in a sector where any vulnerability is something that we have to attempt to remediate, even if it is a tool or library that is installed in a docker image that is not executable by the app that is running inside that container (think base image has a security flaw)... it means we have a lot of work to basically copy the contents of the app out of a container and plug it into our own base images that we can control/scan/deal with the vulnerabilities on. It's a giant pain in the behind. Vendors usually don't care because they rightfully so say "that library is not something our app uses, so it is out of scope" or "that comes installed by default in the debian base image from docker, complain to them".
The field is simply too fast and large. The other one is when your binary/app is using a library that is vulnerable. Think Java/Go/Rust/Python/Ruby using a library that is vulnerable. We can't patch that (without potentially breaking things), so we have to get an exception while we push the vendor to upgrade.
That part is even difficult at times though because sometimes the version that is not vulnerable is not API compatible with the version that is, and the upgrade takes longer than the time we have to remediate the vulnerability. With Ruby/Python/Java we can usually replace the bits necessary to make it not vulnerable and get an exception granted, but for Go/Rust and or other binaries we are stuck getting exception approval and building additional security around the product to make sure that exploit can't be attacked.
> 2. Is anyone aware of a security database & evaluation tool geared for vendors not for end-users? As in: Gets a feed of CVEs relevant for our products, each of them needs to be analyzed, amended, new CVSS vector and our own analyze result and then publish them to a feed, potentially emailing all affected customers
Even if you made this available, we HAVE to use the NVD/CVE scores themselves. We can't deviate just because the vendor says so, unfortunately.
I would love for vendors to have something like this integrated though as some vendors have hopelessly outdated versions of libraries in their products because it is a lot of work for their teams to upgrade/test/validate that the new version doesn't break anything versus just sticking with the known quantity. Upgrading dependencies in a project is work, and the larger the project, the more dependencies, unless you have a really good testing framework it becomes a HUGE chore, and there is always some new feature that gets priority over gardening tasks.