aboutcode-org / aboutcode-org/vulnerablecode

One vulnerability affecting different packages.

未關閉
#1,193 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Core models data-quality
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

A vulnerability is identified in one application and an advisory is generated that corresponds to the application and the vulnerability. Different versions of the package might be vulnerable to the same vulnerability and might be provided by different upstreams (say debian, ubuntu, pypi etc) but the source code of the package remains more or less the same.

If some package depends on a vulnerable package, then marking the parent package as vulnerable is not the accepted approach and data sources mentioning them are considered to be _Crying Wolf_. It is not the job of VulnerableCode to establish the parent-child relationship between packages (perhaps better done via scancode).

VulnerableCode database is hosting affected packages with different names under one vulnerability.
Eg: https://public.vulnerablecode.io/vulnerabilities/VCID-kz2t-1jdd-aaaf?search=CVE-2018-3258
Affected packages are 449 and scrolling down shows lots of different packages.

This looks like a problem caused via the **redhat importer**.
Related: https://github.com/nexB/vulnerablecode/issues/1084

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。