aboutcode-org / aboutcode-org/vulnerablecode

Add the `weaknesses` data in the API `packages` endpoint.

未關閉
#1,632 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Priority: high
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

https://public.vulnerablecode.io/api/vulnerabilities/7567

```
...
"weaknesses": [
{
"cwe_id": 352,
"name": "Cross-Site Request Forgery (CSRF)",
"description": "The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request."
},
{
"cwe_id": 1035,
"name": "OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities",
"description": "Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2017."
},
{
"cwe_id": 937,
"name": "OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities",
"description": "Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2013."
}
],
...
```

This is essential data to collect but it is missing from the `affected_by_vulnerabilities` data structure.
For example https://public.vulnerablecode.io/api/packages/156170

Make sure to add the proper QuerySet optimization (prefetch_related).

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。