aboutcode-org / aboutcode-org/vulnerablecode

Alpine: possibly wrong information is indexed

未關閉
#915 7 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

As I mentioned in #801 there is an issue with the way Alpine packages are indexed.

The following example illustrates this:

https://git.alpinelinux.org/aports/tree/main/py3-jinja2/APKBUILD?id=8531e658bb1a196c87ac3e8abf0bb18022266aa5

This `APKBUILD` file says the version of the package is `2.11.3-r0`. But at line 18 there is a different version number:

```
# secfixes:
# 1.11.3-r0:
# - CVE-2020-28493
```

It looks like someone made a typo in the version number and it is *this* number that VulnerableCode seems to be using (as demonstrated in #801 ).

The solution is to do a little clean up and cross correlate this information with the Alpine package information.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。