aboutcode-org / aboutcode-org/vulnerablecode

Qualify vulnerability references better

未关闭
#1,637 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

From a chat with @mjherzog :

We are returning in some cases too many references - Reference URLs. The volume of data can be overwhelming for popular vulnerabilities.

Eventually we need to qualify, sort and triage these references to make it easier to "triage" the references to focus on the higher value references. For example GitHub commit or pull request references should be very helpful if you are trying to analyze the impact of a vulnerability on your code, but references to discussion threads may be tangential.

It could also mean moving some references to packages or to the package-advisory intersection and create dedicated models for some reference data types.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。