aboutcode-org / aboutcode-org/vulnerablecode

Report only the "best" fixed version that has no vulnerabilities of its own?

未关闭
#1,252 1 条评论 0 个 reaction 已指派 1 人 已被 @johnmhoran 认领 在 GitHub 查看
API enhancement ui
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

This is related to "Report only those fixed versions that are greater than the affected version" #1228.

The question:

Do we want to display/report the most relevant/best `fixed by` version -- however we define "relevant"/"best" -- or do we also want to check whether that version has any vulnerabilities of its own and display/report only a vulnerability-free `fixed by` version? The way we currently define `fixed by` and organize the data in the DB, there are instances where all of the `fixed by` versions have vulnerabilities of their own -- none has 0 vulnerabilities.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。