aboutcode-org / aboutcode-org/vulnerablecode

Confirm that importers filter out CVE Status "REJECT" and NVD Status "Rejected"

未關閉
#1,251 1 則留言 0 個 reaction 已指派 1 人 已被 @TG1999 認領 在 GitHub 檢視
question
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

Please refer to https://nvd.nist.gov/vuln/vulnerability-status

In the "CVE List Statuses" table, note:
`REJECT | ... As a rule, REJECT CVE Entries should be ignored.`

In the "NVD Statuses" table, note:
`Rejected | CVE has been marked as "**REJECT**" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.`

Both Statuses are essentially "noise" and it seems that the associated CVE/NVD's should not be selected for VulnerableCode data, since they are only a distraction and add no value to VulnerableCode.

If VC is already filtering such entries out, please simply confirm and close this issue; otherwise, please improve the importers (and possibly the improvers) to filter them out.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。