aboutcode-org / aboutcode-org/vulnerablecode
Ignore duplicate commit URLs from forked repositories
- 主要言語
- Python
- スター
- 702
- フォーク
- 328
- 平均マージ
- 3日 8時間
- マージ済み PR(30日)
- 3
説明
Some vulnerabilities contain multiple `commit_url` entries that reference the same commit hash in different repositories.
For example:
https://github.com/pypa/advisory-database/blob/main/vulns/requests/PYSEC-2015-17.yaml
https://public.vulnerablecode.io/advisories/pypa/requests/PYSEC-2015-17
The advisory contains the following commit URLs:
* https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc
* https://github.com/psf/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc
Both URLs point to the same Git commit (`3bd8afbff29e50b38f889b2f688785a669b9aafc`). The `kennethreitz/requests` repository is forked repository, while `psf/requests` is the current original repository.
To avoid duplicate patch commits, we should ignore commit URLs from forked repositories when the same commit is available in the original repository
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。