aboutcode-org / aboutcode-org/vulnerablecode

Add types in reference URLs

オープン
#712 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
enhancement
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

## Context
Many vulnerability database designs have a support for types of given reference URLs. For eg:
### NVD
image
Schema:

- https://github.com/CVEProject/cve-schema/blob/master/schema/v5.0/CVE_JSON_5.0_schema.json
- https://github.com/CVEProject/cve-schema/blob/master/schema/v5.0/tags/reference-tags.json

### OSV
https://ossf.github.io/osv-schema/#references-field

## Proposal
Having the _type_ of reference might help in future to filter out the patches and exploits from other references.
It is not sure that we want to restrict our reference types to a few choices as done by OSV and NVD.
Further, we are not inferring the type of reference by our own but trust the upstream.

Thus, we are considering having a ``JSONField`` with contents like ``nvd:customer-entitlement, osv:fix, osv:web`` for reference type.
It is a ``JSONField`` and not a postgres ``Array`` because ``Arrays`` are specific to postgres but ``JSONFields`` are available in other dbs as well.

_(via: https://github.com/nexB/vulnerablecode/wiki/WeeklyMeetings#meeting-on-tuesday-2022-04-26-at-1000-utc)_

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。