aboutcode-org / aboutcode-org/vulnerablecode

Process unstructured data sources, such as issues

未關閉
#251 8 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Data collection
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

These contain valuable data nuggets among an ocean of junk and we need to be able to find the good things there.

Some sources are:

- mailing lists such as:
- https://github.com/nexB/vulnerablecode/issues/100
- https://github.com/nexB/vulnerablecode/issues/104
- https://github.com/nexB/vulnerablecode/issues/108
- changelogs https://github.com/nexB/vulnerablecode/issues/233
- reflogs of commit (see also the commits from vulncodedb and SAP/Eclipse steady KB)
- bug and issue trackers (such as Django, etc)
- actual description of a CVE or the text body of advisories. See https://github.com/nexB/vulnerablecode/issues/551

We can either automate it all, but that's going to be super difficult, or rather start to craft a curation queue and parse as much as we can to make it easy to curate by humans
- https://github.com/nexB/vulnerablecode/issues/218

... and progressively also improve some mini AI and classification to help further automate the work.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。