aboutcode-org / aboutcode-org/vulnerablecode

NVD importer migration followups

Abierto
#679 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Python
Estrellas
702
Forks
328
Merge medio
3 d 8 h
PR fusionados (30 d)
3

Descripción

@pombredanne I am starting this issue to track your comments in #664

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845768104_

> Why do you remove the CVEs from references?
> We still want them there IMHO ... in particular that's where we would get the severity score from the NVD?
>

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845771397_

> You are returning a set not a list. Should your return a sorted list then? Why using a set?

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845772878_

> It could make sense to:
> 1. extract the function to check if a single CVE is related to hardware
> 2. have a set of tests for this that would be easier to read including explicit tests with CPE 2.2 and 2.3 that are hardware or not.
>
> How many types of CPEs is there beyond hardware?

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.