aboutcode-org / aboutcode-org/vulnerablecode

Report only the "best" fixed version that has no vulnerabilities of its own?

未關閉
#1,252 1 則留言 0 個 reaction 已指派 1 人 已被 @johnmhoran 認領 在 GitHub 檢視
API enhancement ui
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

This is related to "Report only those fixed versions that are greater than the affected version" #1228.

The question:

Do we want to display/report the most relevant/best `fixed by` version -- however we define "relevant"/"best" -- or do we also want to check whether that version has any vulnerabilities of its own and display/report only a vulnerability-free `fixed by` version? The way we currently define `fixed by` and organize the data in the DB, there are instances where all of the `fixed by` versions have vulnerabilities of their own -- none has 0 vulnerabilities.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。