aboutcode-org / aboutcode-org/vulnerablecode
Handling of locally patched packagaes
- 主要語言
- Python
- 星號
- 702
- 分支
- 328
- 平均合併
- 3 天 8 小時
- 30 天內合併 PR
- 3
描述
Suppose there is a CVE that affects the package `pkg:maven/org.apache.logging.log4j/log4j@2.16.0` and there is no official fix available. In this scenario, I have two options:
1. Patch the library locally to create a modified version, such as `pkg:maven/org.apache.logging.log4j/log4j@2.16.0-patched` but do not publish it publicly.
2. Patch the library and then republish it to maven under new namespace, like `pkg:maven/com.example/org.apache.logging.log4j@2.16.0-patched`
The second option, for all practical purposes, creates a separate package. However, if I choose the first option and at a later stage, I'm trying to identify vulnerable packages in my project, `pkg:maven/org.apache.logging.log4j/log4j@2.16.0-patched` should not be reported as vulnerable to the same CVE.
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。