aboutcode-org / aboutcode-org/vulnerablecode
Add step in ToDo computation pipeline to detect inconsistent affected and fixed versions in an advisory
未关闭
data-quality
- 主要语言
- Python
- 星标
- 702
- 派生
- 328
- 平均合并
- 3 天 8 小时
- 30 天内合并 PR
- 3
描述
Advisories like https://github.com/nodejs/security-wg/blob/main/vuln/npm/92.json contain inconsistent affected and fixed versions. Here `pkg:npm/express-restify-mongoose` is reported as both affected and fixed in version `3.0.0` which is impossible and should be detected in the ToDo pipeline for human curation.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。