aboutcode-org / aboutcode-org/vulnerablecode
Some references could be treated as aliases
- 主要語言
- Python
- 星號
- 702
- 分支
- 328
- 平均合併
- 3 天 8 小時
- 30 天內合併 PR
- 3
描述
There should be improvers which would take references, verify them as valid unique aliases and add them.
Below documents refers to same RHSA but it is not sure that they are aliases to this particular advisory
Eg:
```py
"advisory": {
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-6mq2-37j5-w6r6"
},
{
"type": "CVE",
"value": "CVE-2009-4492"
}
],
"summary": "Moderate severity vulnerability that affects webrick",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4492"
},
{
"url": "https://github.com/advisories/GHSA-6mq2-37j5-w6r6"
},
{
"url": "http://secunia.com/advisories/37949"
},
{
"url": "http://securitytracker.com/id?1023429"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-0908.html"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-0909.html"
},
{
"url":
"http://www.ruby-lang.org/en/news/2010/01/10/webrick-escape-sequence-injection"
},
{
"url": "http://www.securityfocus.com/archive/1/508830/100/0/threaded"
},
{
"url": "http://www.securityfocus.com/bid/37710"
},
{
"url": "http://www.ush.it/team/ush/hack_httpd_escape/adv.txt"
},
{
"url": "http://www.vupen.com/english/advisories/2010/0089"
}
],
"severity": "MODERATE",
"publishedAt": "2017-10-24T18:33:38Z"
},
"package": {
"name": "webrick"
},
"vulnerableVersionRange": "<= 1.3.1"
}
```
_via: https://github.com/nexB/vulnerablecode/wiki/WeeklyMeetings#meeting-on-tuesday-2022-03-15-at-0900-utc_
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。