aboutcode-org / aboutcode-org/vulnerablecode

Alpine: possibly wrong information is indexed

未关闭
#915 7 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

As I mentioned in #801 there is an issue with the way Alpine packages are indexed.

The following example illustrates this:

https://git.alpinelinux.org/aports/tree/main/py3-jinja2/APKBUILD?id=8531e658bb1a196c87ac3e8abf0bb18022266aa5

This `APKBUILD` file says the version of the package is `2.11.3-r0`. But at line 18 there is a different version number:

```
# secfixes:
# 1.11.3-r0:
# - CVE-2020-28493
```

It looks like someone made a typo in the version number and it is *this* number that VulnerableCode seems to be using (as demonstrated in #801 ).

The solution is to do a little clean up and cross correlate this information with the Alpine package information.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。