aboutcode-org / aboutcode-org/vulnerablecode

Collect apache project's machine readable advisories.

未关闭
#314 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Data collection
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

In any case we want to avoid parsing human readable advisories, so to break https://github.com/nexB/vulnerablecode/issues/100 in smaller manageable parts , we should always parse machine readable advisories if possible.

Apache projects maintain machine readable security advisories at a project level. See for example

https://github.com/apache/syncope/blob/fa82b8266c0c664c49d010d397a9ffb3f6ab4555/src/site/xdoc/security.xml
https://github.com/apache/ofbiz-site/blob/8a3e9fb778858257fd1b930e51059f5a61d2457a/template/page/security.tpl.php
https://github.com/search?q=org%3Aapache+cve&type=code

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。