github / github/codeql

CVSS Score using CSV Output Format

Đang mở
#13,650 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

Is there a way to have the CVSS score be included in the information that's output when the "database analyze" command is run? I know there SARIF format includes the CVSS score under the "security-severity" attribute, but the CSV output is more useful for my current purposes, and the CVSS score is valuable information that I would like to have included in that format.

If anyone could help me out, I'd appreciate it a lot.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start by locating the implementation and tests for the `database analyze` command's CSV output, then compare how SARIF exposes the `security-severity` attribute. The work is complete when the CSV output includes the CVSS score in a documented, tested column.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Lĩnh vực
cli, security
Loại issue
Tính năng
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.