aboutcode-org / aboutcode-org/vulnerablecode

Should we use a different source of JSON advisory/CVE objects for the apache_httpd importer?

Aberta
#1,018 0 comentários 0 reações 1 responsável Reivindicada por @johnmhoran Ver no GitHub
Data collection import-improver-migration
Linguagem predominante
Python
Estrelas
702
Forks
328
Merge médio
3d 8h
PRs com merge (30d)
3

Descrição

Exploring the `json` URL we currently use in the `apache_httpd.py` `fetch_links()` function (https://httpd.apache.org/security/json/), if I navigate up 1 step to https://httpd.apache.org/security/, I see that:

* The date of the `json` folder is 2022-06-10. This folder contains the individual `.json` files currently parsed by `fetch_links()`. 1 file is dated 2022-06-10, and all others are dated 2022-06-08.
* There's also a link to https://httpd.apache.org/security/vulnerabilities-httpd.json, dated 2022-10-24, which is a list of `.json` advisory/CVE objects, possibly containing all of the individual CVE objects (and more?).

Should we explore this list of advisory/CVE objects, determine whether it contains all the objects contained in the `json` folder we're currently parsing, and if so parse that file instead, since it has a more recent date?

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.