aboutcode-org / aboutcode-org/aboutcode

When patching packages, design how to track modifications

未关闭
#158 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Batchfile
星标
302
派生
249
平均合并
1 天 9 小时
30 天内合并 PR
2

描述

When a package is modified locally in a codebase, we should be able track these modifications and how to identify them.

Why? Because a package may have been:

1. patched for a regular bug
2. patched for a security vulnerability
3. patched for a new or altered feature
4. updated for corrected metadata (such as origin, license, dependencies)
5. renamed or its version changed (or not :] )

In all these cases, we may have some problems if we do not known about this:
- we may report it as vulnerable when this is not the case
- we may not report it as vulnerable when this is the case
- we may match it it incorrectly to an upstream version or an altered version

Tracking could be done in ABOUT files, in DejaCode and the PurlDB and be used by downstream processes to avoid false negative and false positive lookups. This is especially important when we have renamed packages that are patched but where the original unpatched package and the patched version could be both vulnerable.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。