aboutcode-org / aboutcode-org/vulnerablecode

NVD importer migration followups

Offen
#679 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
702
Forks
328
Ø Merge
3 T. 8 Std.
Gemergte PRs (30 T.)
3

Beschreibung

@pombredanne I am starting this issue to track your comments in #664

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845768104_

> Why do you remove the CVEs from references?
> We still want them there IMHO ... in particular that's where we would get the severity score from the NVD?
>

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845771397_

> You are returning a set not a list. Should your return a sorted list then? Why using a set?

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845772878_

> It could make sense to:
> 1. extract the function to check if a single CVE is related to hardware
> 2. have a set of tests for this that would be easier to read including explicit tests with CPE 2.2 and 2.3 that are hardware or not.
>
> How many types of CPEs is there beyond hardware?

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.