aboutcode-org / aboutcode-org/vulnerablecode
Add step in ToDo computation pipeline to detect inconsistent affected and fixed versions in an advisory
Open
data-quality
- Dominant language
- Python
- Stars
- 702
- Forks
- 328
- Avg merge
- 3d 8h
- Merged PRs (30d)
- 3
Description
Advisories like https://github.com/nodejs/security-wg/blob/main/vuln/npm/92.json contain inconsistent affected and fixed versions. Here `pkg:npm/express-restify-mongoose` is reported as both affected and fixed in version `3.0.0` which is impossible and should be detected in the ToDo pipeline for human curation.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.