CodeQL maps CWE-730, which MITRE prohibits from being used for mapping
未关闭
question
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 15 小时
- 30 天内合并 PR
- 141
描述
CodeQL maps weakness CWE-730 on Code Scanning alerts. According to [MITRE](https://cwe.mitre.org/data/definitions/730.html), CWE-730 is a Category and it is marked PROHIBITED (this CWE ID must not be used to map to real-world vulnerabilities).
Also note that this CWE is not listed in [CodeQL's CWE coverage](https://codeql.github.com/codeql-query-help/full-cwe/) page in the docs.
贡献指南
调研方向
Start by comparing the CodeQL alert mapping for CWE-730 with MITRE's definition and prohibition notice. Then inspect the CodeQL CWE coverage documentation to determine how the mapping is represented. Done means prohibited CWE-730 is no longer mapped to alerts and the documented coverage is consistent.
由索引模型根据 Issue 内容生成。
评估
- 领域
- documentation, security
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 55/100