aboutcode-org / aboutcode-org/vulnerablecode

Add date of publishing in vulnerability detail view

未關閉
#1,355 3 則留言 0 個 reaction 已指派 2 人 已被 @TG1999 認領 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

ATM in VCIO a vulnerability is an object created by the culmination of multiple advisories. We will use the NVD importer publish date as default for each vulnerability, in case an advisory from the NVD is not being used in that vulnerability we will use the most oldest publishing date from other importers' advisory.

Ways to achieve this:

- 1.) Store two DateTime fields in the vulnerability model, `nvd_published_date` and `latest_published_date`. We will populate `nvd_published_date` with the date/time of the NVD advisory publishing date and and `latest_published_date` will be keep changing as new advisories add any data in the Vulnerability, if we have `nvd_published_date` for a vulnerability we will always use it as a default date.

- 2.) For every vulnerability, get a list of advisories that have the aliases of that vulnerability. If any advisory from that list is from the NVD use that date otherwise use the oldest date of publish among those advisories

- 3.) Store a list of advisories that are used in the creation of that vulnerability in the Vulnerability model and compute the date of publish from that list of advisories. If any advisory from that list is from the NVD use that otherwise use the oldest date of publish among those advisories

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。