aboutcode-org / aboutcode-org/vulnerablecode

Confirm that importers filter out CVE Status "REJECT" and NVD Status "Rejected"

Offen
#1,251 1 Kommentar 0 Reaktionen 1 zugewiesene Person Beansprucht von @TG1999 Auf GitHub ansehen
question
Vorherrschende Sprache
Python
Sterne
702
Forks
328
Ø Merge
3 T. 8 Std.
Gemergte PRs (30 T.)
3

Beschreibung

Please refer to https://nvd.nist.gov/vuln/vulnerability-status

In the "CVE List Statuses" table, note:
`REJECT | ... As a rule, REJECT CVE Entries should be ignored.`

In the "NVD Statuses" table, note:
`Rejected | CVE has been marked as "**REJECT**" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.`

Both Statuses are essentially "noise" and it seems that the associated CVE/NVD's should not be selected for VulnerableCode data, since they are only a distraction and add no value to VulnerableCode.

If VC is already filtering such entries out, please simply confirm and close this issue; otherwise, please improve the importers (and possibly the improvers) to filter them out.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.