aboutcode-org / aboutcode-org/vulnerablecode

Report only the "best" fixed version that has no vulnerabilities of its own?

Abierto
#1,252 1 comentario 0 reacciones 1 asignado Reclamado por @johnmhoran Ver en GitHub
API enhancement ui
Lenguaje dominante
Python
Estrellas
702
Forks
328
Merge medio
3 d 8 h
PR fusionados (30 d)
3

Descripción

This is related to "Report only those fixed versions that are greater than the affected version" #1228.

The question:

Do we want to display/report the most relevant/best `fixed by` version -- however we define "relevant"/"best" -- or do we also want to check whether that version has any vulnerabilities of its own and display/report only a vulnerability-free `fixed by` version? The way we currently define `fixed by` and organize the data in the DB, there are instances where all of the `fixed by` versions have vulnerabilities of their own -- none has 0 vulnerabilities.

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.