aboutcode-org / aboutcode-org/vulnerablecode
Handle Gitlab false positive
- 主要语言
- Python
- 星标
- 702
- 派生
- 328
- 平均合并
- 3 天 8 小时
- 30 天内合并 PR
- 3
描述
This https://gitlab.com/gitlab-org/advisories-community/-/blob/main/maven/org.owasp.antisamy/antisamy/CVE-2023-49093.yml started as an advisory and then became a "False positive"
Gitlab updates the description and title in these cases, and there are 150+ such advisories.
The outcome is invalid data. We should support these and update accordingly
See https://public.vulnerablecode.io/packages/pkg:maven/org.owasp.antisamy/antisamy@1.7.4?search=antisamy
There https://public.vulnerablecode.io/vulnerabilities/VCID-zx5k-4m3n-aaaj does NOT apply to antisamy

See attached for a list of patterns found in GitLab advisories
[fp.txt](https://github.com/nexB/vulnerablecode/files/14757642/fp.txt)
@julianthome gentle ping... do you know if there is a list of patterns we can track? Thanks!
In the same domain, we should also find is there are other related unstructured patterns in GitLab and also:
- [ ] Handle "Disputed" markers in CVEs texts
- [ ] Handle "Awaiting Analysis" in CVEs
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。