aboutcode-org / aboutcode-org/vulnerablecode

Add the `weaknesses` data in the API `packages` endpoint.

Aberta
#1,632 1 comentário 0 reações 0 responsáveis Ver no GitHub
Priority: high
Linguagem predominante
Python
Estrelas
702
Forks
328
Merge médio
3d 8h
PRs com merge (30d)
3

Descrição

https://public.vulnerablecode.io/api/vulnerabilities/7567

```
...
"weaknesses": [
{
"cwe_id": 352,
"name": "Cross-Site Request Forgery (CSRF)",
"description": "The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request."
},
{
"cwe_id": 1035,
"name": "OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities",
"description": "Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2017."
},
{
"cwe_id": 937,
"name": "OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities",
"description": "Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2013."
}
],
...
```

This is essential data to collect but it is missing from the `affected_by_vulnerabilities` data structure.
For example https://public.vulnerablecode.io/api/packages/156170

Make sure to add the proper QuerySet optimization (prefetch_related).

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.