aboutcode-org / aboutcode-org/vulnerablecode
Add step in ToDo computation pipeline to detect inconsistent affected and fixed versions in an advisory
Abierto
data-quality
- Lenguaje dominante
- Python
- Estrellas
- 702
- Forks
- 328
- Merge medio
- 3 d 8 h
- PR fusionados (30 d)
- 3
Descripción
Advisories like https://github.com/nodejs/security-wg/blob/main/vuln/npm/92.json contain inconsistent affected and fixed versions. Here `pkg:npm/express-restify-mongoose` is reported as both affected and fixed in version `3.0.0` which is impossible and should be detected in the ToDo pipeline for human curation.
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Evaluación
Este issue todavía no se ha evaluado.