aboutcode-org / aboutcode-org/vulnerablecode

Collect commits from dependabot

未关闭
#1,130 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
fix-commit
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

We should mine and store the commits made from dependabot in vulnerablecode database.

- Get all the dependabot commits
- Check the package mentioned in that commit is vulnerable or not for example: https://github.com/KoraLinSar/python-socketio/commit/a79f81b8346ab58b012910375569c5d913f0146c this states `Bump sanic from 0.8 to 20.12.6 in /examples/server/sanic` here sanice@0.8 might be vulnerable which can be checked from vulnerablecode https://public.vulnerablecode.io/packages/pkg:pypi/sanic@0.8.0?search=sanic this means this commit is fixing a vulnerable package and the current release of that package can be marked as vulnerable.
- Also check if the commit is merged in main, sometimes dependabot commits might be changing the mock data in test files

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。