aboutcode-org / aboutcode-org/vulnerablecode

Should we use a different source of JSON advisory/CVE objects for the apache_httpd importer?

未關閉
#1,018 0 則留言 0 個 reaction 已指派 1 人 已被 @johnmhoran 認領 在 GitHub 檢視
Data collection import-improver-migration
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

Exploring the `json` URL we currently use in the `apache_httpd.py` `fetch_links()` function (https://httpd.apache.org/security/json/), if I navigate up 1 step to https://httpd.apache.org/security/, I see that:

* The date of the `json` folder is 2022-06-10. This folder contains the individual `.json` files currently parsed by `fetch_links()`. 1 file is dated 2022-06-10, and all others are dated 2022-06-08.
* There's also a link to https://httpd.apache.org/security/vulnerabilities-httpd.json, dated 2022-10-24, which is a list of `.json` advisory/CVE objects, possibly containing all of the individual CVE objects (and more?).

Should we explore this list of advisory/CVE objects, determine whether it contains all the objects contained in the `json` folder we're currently parsing, and if so parse that file instead, since it has a more recent date?

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。