aboutcode-org / aboutcode-org/vulnerablecode
Handle Gitlab false positive
- Dominant language
- Python
- Stars
- 702
- Forks
- 328
- Avg merge
- 3d 8h
- Merged PRs (30d)
- 3
Description
This https://gitlab.com/gitlab-org/advisories-community/-/blob/main/maven/org.owasp.antisamy/antisamy/CVE-2023-49093.yml started as an advisory and then became a "False positive"
Gitlab updates the description and title in these cases, and there are 150+ such advisories.
The outcome is invalid data. We should support these and update accordingly
See https://public.vulnerablecode.io/packages/pkg:maven/org.owasp.antisamy/antisamy@1.7.4?search=antisamy
There https://public.vulnerablecode.io/vulnerabilities/VCID-zx5k-4m3n-aaaj does NOT apply to antisamy

See attached for a list of patterns found in GitLab advisories
[fp.txt](https://github.com/nexB/vulnerablecode/files/14757642/fp.txt)
@julianthome gentle ping... do you know if there is a list of patterns we can track? Thanks!
In the same domain, we should also find is there are other related unstructured patterns in GitLab and also:
- [ ] Handle "Disputed" markers in CVEs texts
- [ ] Handle "Awaiting Analysis" in CVEs
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.