aboutcode-org / aboutcode-org/vulnerablecode

How to detect link between a vulnerability and source code of project?

オープン
#1,216 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
Core models
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

As an example, consider this security advisory: https://github.com/mongo-express/mongo-express/security/advisories/GHSA-7p8h-86p5-wv3p

The CVE related to this advisory is "CVE-2021-21422". In this project(vulnerablecode), we can detect the relation between CVE and the package manager, which is npm in this case. However, I couldn't find a way to detect a link between a CVE and the project source code. It's also possible for some open source projects that they wouldn't have any package manager at all. Is adding the link between a vulnerability and a the project source code a possible\planned\in-scope feature for this project? My goal is to have a relation between a package and upstream source code. This way, we can link a many package to a github\gitlab\bitbucket project. Then for each project link, we can other metadata of the project as well. If we can discuss it further I might be able implement it.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。