aboutcode-org / aboutcode-org/vulnerablecode

v30 changelog highlights

オープン
#936 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

- Enhanced models and migrated Nginx, Github, Alpine, NVD, OpenSSL and Redhat Importer.
- Enhanced the web UI with a brand new UI based on the same overall look and feel as [ScanCode.io](http://scancode.io/).
- Added new importers like PYSEC, Pypi and GitLab
- Added aliases of a vulnerability in the API vulnerabilities/ endpoint.
- Added a new `cpe/` API endpoint to lookup for vulnerabilities by CPE and another aliases/ endpoint to lookup for vulnerabilities by aliases
- Added bulk search support for CPEs.
- Added fixed packages in vulnerability details in packages endpoint
- Enhanced Package endpoint will give fixed packages of only those that matches type, name, namespace, subpath and qualifiers of the package queried.
- Added filters for vulnerabilities endpoint to get fixed packages in accordance to the details given in filters: For example, when you call the endpoint this way ``/api/vulnerabilities?type=pypi&namespace=foo&name=bar``, you will receive only fixed versioned purls of the type ``pypi``, namespace ``foo`` and name ``bar``.
- Added is_vulnerable property to fixed and affected package in packages endpoint
- Added authentication for REST API endpoint.
- Added data license CC-BY-SA-4.0 as this is the highest common denominator license among all the data sources we collect and aggregate.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。