aboutcode-org / aboutcode-org/vulnerablecode

Handling of locally patched packagaes

オープン
#1,329 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

Suppose there is a CVE that affects the package `pkg:maven/org.apache.logging.log4j/log4j@2.16.0` and there is no official fix available. In this scenario, I have two options:

1. Patch the library locally to create a modified version, such as `pkg:maven/org.apache.logging.log4j/log4j@2.16.0-patched` but do not publish it publicly.

2. Patch the library and then republish it to maven under new namespace, like `pkg:maven/com.example/org.apache.logging.log4j@2.16.0-patched`

The second option, for all practical purposes, creates a separate package. However, if I choose the first option and at a later stage, I'm trying to identify vulnerable packages in my project, `pkg:maven/org.apache.logging.log4j/log4j@2.16.0-patched` should not be reported as vulnerable to the same CVE.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。