aboutcode-org / aboutcode-org/vulnerablecode

Ignore duplicate commit URLs from forked repositories

Open
#2,361 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

Some vulnerabilities contain multiple `commit_url` entries that reference the same commit hash in different repositories.

For example:
https://github.com/pypa/advisory-database/blob/main/vulns/requests/PYSEC-2015-17.yaml
https://public.vulnerablecode.io/advisories/pypa/requests/PYSEC-2015-17

The advisory contains the following commit URLs:

* https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc
* https://github.com/psf/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc

Both URLs point to the same Git commit (`3bd8afbff29e50b38f889b2f688785a669b9aafc`). The `kennethreitz/requests` repository is forked repository, while `psf/requests` is the current original repository.

To avoid duplicate patch commits, we should ignore commit URLs from forked repositories when the same commit is available in the original repository

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.