aboutcode-org / aboutcode-org/vulnerablecode

Confirm that importers filter out CVE Status "REJECT" and NVD Status "Rejected"

Open
#1,251 1 comment 0 reactions 1 assignee Claimed by @TG1999 View on GitHub
question
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

Please refer to https://nvd.nist.gov/vuln/vulnerability-status

In the "CVE List Statuses" table, note:
`REJECT | ... As a rule, REJECT CVE Entries should be ignored.`

In the "NVD Statuses" table, note:
`Rejected | CVE has been marked as "**REJECT**" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.`

Both Statuses are essentially "noise" and it seems that the associated CVE/NVD's should not be selected for VulnerableCode data, since they are only a distraction and add no value to VulnerableCode.

If VC is already filtering such entries out, please simply confirm and close this issue; otherwise, please improve the importers (and possibly the improvers) to filter them out.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.