aboutcode-org / aboutcode-org/vulnerablecode

Confirm that importers filter out CVE Status "REJECT" and NVD Status "Rejected"

オープン
#1,251 コメント 1 件 リアクション 0 件 担当者 1 名 @TG1999 が担当を希望しています GitHub で見る
question
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

Please refer to https://nvd.nist.gov/vuln/vulnerability-status

In the "CVE List Statuses" table, note:
`REJECT | ... As a rule, REJECT CVE Entries should be ignored.`

In the "NVD Statuses" table, note:
`Rejected | CVE has been marked as "**REJECT**" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.`

Both Statuses are essentially "noise" and it seems that the associated CVE/NVD's should not be selected for VulnerableCode data, since they are only a distraction and add no value to VulnerableCode.

If VC is already filtering such entries out, please simply confirm and close this issue; otherwise, please improve the importers (and possibly the improvers) to filter them out.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。