aboutcode-org / aboutcode-org/vulnerablecode

Incorrect types for `related_ssvc_trees` and `fixed_by_packages` in OpenAPI schema

未关闭
#2,364 1 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

Hi! I noticed another deficiency in the OpenAPI schema, for the `AdvisoryV3` and `AffectedByAdvisoryV3` schemas the `related_ssvc_trees` and `fixed_by_packages` properties are defined as string-type fields

```json
"related_ssvc_trees": {
"type": "string",
"readOnly": true
},
"fixed_by_packages": {
"type": "string",
"readOnly": true
}
```

though `related_ssvc_trees` is an array of objects, and `fixed_by_packages` is an array of strings, so should be something like

```json
"related_ssvc_trees": {
"type": "array",
"items": {
"$ref": "#/components/schemas/RelatedSSVCTree"
},
"readOnly": true
},
"fixed_by_packages": {
"type": "array",
"items": {
"type": "string"
},
"readOnly": true
}
```

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。