aboutcode-org / aboutcode-org/vulnerablecode
RFC: vulnerability reachability
- Langage dominant
- Python
- Étoiles
- 702
- Forks
- 328
- Merge moyen
- 3 j 8 h
- PR mergées (30 j)
- 3
Description
Vulnerability reachability is to check if vulnerable code is reachable or not.
This is important to help triage vulnerabilities.
Some of the things to consider:
- [x] Collecting introducing/fix commits or patches to find vulnerable functions
- [x] https://github.com/nexB/vulnerablecode/issues/207
- [x] Include commits and patches that introduce a vulnerability
- [x] https://github.com/nexB/vulnerablecode/issues/327
- [ ] Finding the path in the affected package code graph to the vulnerable functions
- [ ] Finding the path in the codebase under analysis that may use the affected package vulnerable functions
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Évaluation
Cette issue n'a pas encore été évaluée.