aboutcode-org / aboutcode-org/vulnerablecode

Process unstructured data sources, such as issues

未关闭
#251 8 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Data collection
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

These contain valuable data nuggets among an ocean of junk and we need to be able to find the good things there.

Some sources are:

- mailing lists such as:
- https://github.com/nexB/vulnerablecode/issues/100
- https://github.com/nexB/vulnerablecode/issues/104
- https://github.com/nexB/vulnerablecode/issues/108
- changelogs https://github.com/nexB/vulnerablecode/issues/233
- reflogs of commit (see also the commits from vulncodedb and SAP/Eclipse steady KB)
- bug and issue trackers (such as Django, etc)
- actual description of a CVE or the text body of advisories. See https://github.com/nexB/vulnerablecode/issues/551

We can either automate it all, but that's going to be super difficult, or rather start to craft a curation queue and parse as much as we can to make it easy to curate by humans
- https://github.com/nexB/vulnerablecode/issues/218

... and progressively also improve some mini AI and classification to help further automate the work.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。