aboutcode-org / aboutcode-org/vulnerablecode

Report only the "best" fixed version that has no vulnerabilities of its own?

Open
#1,252 1 comment 0 reactions 1 assignee Claimed by @johnmhoran View on GitHub
API enhancement ui
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

This is related to "Report only those fixed versions that are greater than the affected version" #1228.

The question:

Do we want to display/report the most relevant/best `fixed by` version -- however we define "relevant"/"best" -- or do we also want to check whether that version has any vulnerabilities of its own and display/report only a vulnerability-free `fixed by` version? The way we currently define `fixed by` and organize the data in the DB, there are instances where all of the `fixed by` versions have vulnerabilities of their own -- none has 0 vulnerabilities.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.