aboutcode-org / aboutcode-org/vulnerablecode

We do not collect the affected range for Gitlab advisories

オープン
#2,412 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

See https://public.vulnerablecode.io/advisories/todos/1e80217b-9032-4276-8e5b-170de8ebf750/package/curate/

and https://public.vulnerablecode.io/advisories/packages/gitlab/maven/org.bouncycastle/bcprov-debug-jdk14/CVE-2025-14813

Upstream has these ranges:
https://gitlab.com/gitlab-org/advisories-community/-/blob/main/maven/org.bouncycastle/bcprov-debug-jdk14/CVE-2025-14813.yml
```
affected_range: "[1.59.0,1.80.1],[1.82.0,1.84.0),[1.81.0,1.81.0]"
fixed_versions:
- "1.84.0"
```

- affected_range is missing
- These are subject to the #2411 issue too, but we should collect the affected range
- version `1.84.0` is reported as a ghost because there is no such version upstream
- https://public.vulnerablecode.io/packages/v2/pkg:maven/org.bouncycastle/bcprov-debug-jdk14@1.84.0?search=pkg:maven/org.bouncycastle/bcprov-debug-jdk14@1.84.0
- https://repo1.maven.org/maven2/org/bouncycastle/bcprov-debug-jdk14/1.84/

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。