Adding GHSA from non ecosystem software
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 30/100
Research direction
Start with the repository README’s stated behavior and review the example advisory GHSA-m59c-q9gq-rh2j alongside its project Security page. The issue names no source files or tests; determine whether non-ecosystem advisories are in scope and what repository change or documentation would define completion.
Written by the indexing model from the issue text.
Description
Hello,
i currently started working with the Github Adivsory Database to track vulnerabilities for packages which are not part of any Ecosystem. For example when using https://github.com/mcu-tools/mcuboot they track their vulnerabilities using Github. But the recorded GHSA for example GHSA-m59c-q9gq-rh2j are not listed in the Database.
While i understand that per Readme this behavior is intended I do not really understand the reason.
For my understanding GHSA are already checked by the maintainer of the project before they are listed on the Security Page of the respective project. So i do not understand the benefit of not listing those vulnerabilities to the Database.
Is there any chance that such vulnerabilities could be added to this database?
Best regards
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 15h
- Merged PRs (30d)
- 46
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#9255 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
All issues in github/advisory-database
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Business User Story
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
[Documentation Request] vLLM kv_load_failure_policy doesn't apply to load failures in L2 adapters Open
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
0. Needs triage bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100