aboutcode-org / aboutcode-org/vulnerablecode

Confirm that importers filter out CVE Status "REJECT" and NVD Status "Rejected"

未关闭
#1,251 1 条评论 0 个 reaction 已指派 1 人 已被 @TG1999 认领 在 GitHub 查看
question
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

Please refer to https://nvd.nist.gov/vuln/vulnerability-status

In the "CVE List Statuses" table, note:
`REJECT | ... As a rule, REJECT CVE Entries should be ignored.`

In the "NVD Statuses" table, note:
`Rejected | CVE has been marked as "**REJECT**" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.`

Both Statuses are essentially "noise" and it seems that the associated CVE/NVD's should not be selected for VulnerableCode data, since they are only a distraction and add no value to VulnerableCode.

If VC is already filtering such entries out, please simply confirm and close this issue; otherwise, please improve the importers (and possibly the improvers) to filter them out.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。