aboutcode-org / aboutcode-org/vulnerablecode
Add step in ToDo computation pipeline to detect inconsistent affected and fixed versions in an advisory
未關閉
data-quality
- 主要語言
- Python
- 星號
- 702
- 分支
- 328
- 平均合併
- 3 天 8 小時
- 30 天內合併 PR
- 3
描述
Advisories like https://github.com/nodejs/security-wg/blob/main/vuln/npm/92.json contain inconsistent affected and fixed versions. Here `pkg:npm/express-restify-mongoose` is reported as both affected and fixed in version `3.0.0` which is impossible and should be detected in the ToDo pipeline for human curation.
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。