aboutcode-org / aboutcode-org/vulnerablecode

Qualify vulnerability references better

オープン
#1,637 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

From a chat with @mjherzog :

We are returning in some cases too many references - Reference URLs. The volume of data can be overwhelming for popular vulnerabilities.

Eventually we need to qualify, sort and triage these references to make it easier to "triage" the references to focus on the higher value references. For example GitHub commit or pull request references should be very helpful if you are trying to analyze the impact of a vulnerability on your code, but references to discussion threads may be tangential.

It could also mean moving some references to packages or to the package-advisory intersection and create dedicated models for some reference data types.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。