aboutcode-org / aboutcode-org/vulnerablecode

Improve results for unknown package versions that are in a vulnerable range

Open
#1,552 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

We need to improve the API results we return for unknown package versions that are in a vulnerable range.

Say I have this setup:
- package A has known versions 1,2,4 and 5.
- It is affected by cve1 from version 1 to 4, 5 in fixed
- we find version 3 in a codebase scan, but 3 does note exists upstream
- here a lookup for 3 will report it as non-vulnerable
- but we want to to tell that:

1. it is an unknown version
2. it falls in a vulnerable range

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.