aboutcode-org / aboutcode-org/vulnerablecode

Ignore duplicate commit URLs from forked repositories

未關閉
#2,361 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

Some vulnerabilities contain multiple `commit_url` entries that reference the same commit hash in different repositories.

For example:
https://github.com/pypa/advisory-database/blob/main/vulns/requests/PYSEC-2015-17.yaml
https://public.vulnerablecode.io/advisories/pypa/requests/PYSEC-2015-17

The advisory contains the following commit URLs:

* https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc
* https://github.com/psf/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc

Both URLs point to the same Git commit (`3bd8afbff29e50b38f889b2f688785a669b9aafc`). The `kennethreitz/requests` repository is forked repository, while `psf/requests` is the current original repository.

To avoid duplicate patch commits, we should ignore commit URLs from forked repositories when the same commit is available in the original repository

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。