aboutcode-org / aboutcode-org/vulnerablecode

Decide what info we need to store on a grouped advisory

オープン
#2,341 コメント 0 件 リアクション 0 件 担当者 2 名 @TG1999 が担当を希望しています GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

A grouped advisory is a group of multiple advisories which share common identifiers and have same packages in their affected and fixing ranges.

We need to decide what all information shall be stored on a grouped advisory and how it shall be calculated

Current info we store/show
- identifier - AVID of primary advisory
- aliases - aliases of all advisories
- risk_score - min(exploitability * weighted_severity, 10.0)
- weighted_severity - max severity of an advisory
- exploitability - max exploitability of an advisory
- summary - summary only of primary advisory
- ssvc_tress - all SSVC trees
- fixed_by_packages - they are already same for all advisories

TBD
- references
- weaknesses
- severities

We need to define this

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。