aboutcode-org / aboutcode-org/vulnerablecode

Use `affected` instead of `versionUnaffected` for reporting fixed versions from DEPS

未关闭
#1,153 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement VulnTotal
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

Currently, we're reporting `versionUnaffected` as the fixed version which is not precisely the fixed version.
We can make use of `affected` to get the fixed version.

```json
"affected": "{[0.0.0-0:2.1.3)}",
"rawAffected": "Introduced: 0, Fixed: 2.1.3",
```
![Screenshot 2023-03-17 at 1 39 00 PM](https://user-images.githubusercontent.com/44315208/225856783-58d4a131-f40a-4eee-9a3c-027b476e1d69.png)




> **Warning**
> Don't use `rawAffected` as it's susceptible to change as shown below
>
> [GHSA-jfh8-c2jp-5v3q (as on 17-Mar-2023)](https://web.archive.org/web/20230317090918/https://deps.dev/_/advisory/osv/GHSA-jfh8-c2jp-5v3q)
> ```json
> "affected": "{[0.alpha:2.3.1),[2.4:2.12.2),[2.13:2.15)}"
> "rawAffected": "Introduced: 2.13.0, Fixed: 2.15.0, Introduced: 0, Fixed: 2.3.1, Introduced: 2.4, Fixed: 2.12.2"
> ```
>
> [GHSA-jfh8-c2jp-5v3q (as on 22-Dec-2022)](https://web.archive.org/web/20221216222510/https://deps.dev/_/advisory/GHSA/GHSA-jfh8-c2jp-5v3q)
> ```json
> "affected": "{[2.4:2.12.2),[0.alpha:2.3.1),[2.13:2.15)}",
> "rawAffected": ">= 2.4, < 2.12.2 or < 2.3.1 or >= 2.13.0, < 2.15.0",
> ```

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。