aboutcode-org / aboutcode-org/vulnerablecode
v30 changelog highlights
- Langage dominant
- Python
- Étoiles
- 702
- Forks
- 328
- Merge moyen
- 3 j 8 h
- PR mergées (30 j)
- 3
Description
- Enhanced models and migrated Nginx, Github, Alpine, NVD, OpenSSL and Redhat Importer.
- Enhanced the web UI with a brand new UI based on the same overall look and feel as [ScanCode.io](http://scancode.io/).
- Added new importers like PYSEC, Pypi and GitLab
- Added aliases of a vulnerability in the API vulnerabilities/ endpoint.
- Added a new `cpe/` API endpoint to lookup for vulnerabilities by CPE and another aliases/ endpoint to lookup for vulnerabilities by aliases
- Added bulk search support for CPEs.
- Added fixed packages in vulnerability details in packages endpoint
- Enhanced Package endpoint will give fixed packages of only those that matches type, name, namespace, subpath and qualifiers of the package queried.
- Added filters for vulnerabilities endpoint to get fixed packages in accordance to the details given in filters: For example, when you call the endpoint this way ``/api/vulnerabilities?type=pypi&namespace=foo&name=bar``, you will receive only fixed versioned purls of the type ``pypi``, namespace ``foo`` and name ``bar``.
- Added is_vulnerable property to fixed and affected package in packages endpoint
- Added authentication for REST API endpoint.
- Added data license CC-BY-SA-4.0 as this is the highest common denominator license among all the data sources we collect and aggregate.
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Évaluation
Cette issue n'a pas encore été évaluée.