aboutcode-org / aboutcode-org/vulnerablecode
Collect commits from dependabot
- 主要語言
- Python
- 星號
- 702
- 分支
- 328
- 平均合併
- 3 天 8 小時
- 30 天內合併 PR
- 3
描述
We should mine and store the commits made from dependabot in vulnerablecode database.
- Get all the dependabot commits
- Check the package mentioned in that commit is vulnerable or not for example: https://github.com/KoraLinSar/python-socketio/commit/a79f81b8346ab58b012910375569c5d913f0146c this states `Bump sanic from 0.8 to 20.12.6 in /examples/server/sanic` here sanice@0.8 might be vulnerable which can be checked from vulnerablecode https://public.vulnerablecode.io/packages/pkg:pypi/sanic@0.8.0?search=sanic this means this commit is fixing a vulnerable package and the current release of that package can be marked as vulnerable.
- Also check if the commit is merged in main, sometimes dependabot commits might be changing the mock data in test files
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。