aboutcode-org / aboutcode-org/vulnerablecode

Add step in ToDo computation pipeline to detect inconsistent affected and fixed versions in an advisory

オープン
#2,324 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
data-quality
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

Advisories like https://github.com/nodejs/security-wg/blob/main/vuln/npm/92.json contain inconsistent affected and fixed versions. Here `pkg:npm/express-restify-mongoose` is reported as both affected and fixed in version `3.0.0` which is impossible and should be detected in the ToDo pipeline for human curation.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。