aboutcode-org / aboutcode-org/vulnerablecode
Improve results for unknown package versions that are in a vulnerable range
Open
- Dominant language
- Python
- Stars
- 702
- Forks
- 328
- Avg merge
- 3d 8h
- Merged PRs (30d)
- 3
Description
We need to improve the API results we return for unknown package versions that are in a vulnerable range.
Say I have this setup:
- package A has known versions 1,2,4 and 5.
- It is affected by cve1 from version 1 to 4, 5 in fixed
- we find version 3 in a codebase scan, but 3 does note exists upstream
- here a lookup for 3 will report it as non-vulnerable
- but we want to to tell that:
1. it is an unknown version
2. it falls in a vulnerable range
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.