aboutcode-org / aboutcode-org/vulnerablecode

Add types in reference URLs

未關閉
#712 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
enhancement
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

## Context
Many vulnerability database designs have a support for types of given reference URLs. For eg:
### NVD
image
Schema:

- https://github.com/CVEProject/cve-schema/blob/master/schema/v5.0/CVE_JSON_5.0_schema.json
- https://github.com/CVEProject/cve-schema/blob/master/schema/v5.0/tags/reference-tags.json

### OSV
https://ossf.github.io/osv-schema/#references-field

## Proposal
Having the _type_ of reference might help in future to filter out the patches and exploits from other references.
It is not sure that we want to restrict our reference types to a few choices as done by OSV and NVD.
Further, we are not inferring the type of reference by our own but trust the upstream.

Thus, we are considering having a ``JSONField`` with contents like ``nvd:customer-entitlement, osv:fix, osv:web`` for reference type.
It is a ``JSONField`` and not a postgres ``Array`` because ``Arrays`` are specific to postgres but ``JSONFields`` are available in other dbs as well.

_(via: https://github.com/nexB/vulnerablecode/wiki/WeeklyMeetings#meeting-on-tuesday-2022-04-26-at-1000-utc)_

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。