Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Repo specific advisories with CVE IDs don't make it into the global set

Aperta
#3,266 3 commenti 5 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
30/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
github, grafana

Direzione di ricerca

Inizia con l’advisory Grafana GHSA-2x6g-h2hg-rq84 e confronta il relativo CVE-2022-39306 assegnato con il risultato della ricerca di GitHub Advisory Database. Traccia come vengono gestiti gli advisory specifici del repository con CVE IDs e considera risolto l’issue quando quel CVE è presente nel database globale.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

It looks like if a repo has an advisory that was not marked to enter the global database, and that advisory is assigned a CVE ID, the CVE ID in question is not present in the GitHub Advisory Database.

I feel like I'm not explaining this well, so I have an example.

This Grafana advisory
https://github.com/grafana/grafana/security/advisories/GHSA-2x6g-h2hg-rq84

Has been assigned CVE-2022-39306

If you search the GitHub advisory database, that ID doesn't show up.

It is nice to use the GitHub database, even for unreviewed IDs, because it's vastly more complete and accurate for supported ecosystems than other sources. Incomplete CVE data means multiple data sources must be queried to get a full picture of which IDs exist.

Related is https://github.com/github/advisory-database/issues/2963 where I suggest allowing community contributions for non supported ecosystems, it would be a service to the world to have a public place to store useful details uncovered during investigations

Lingua principale
Nessun dato sulla lingua
Stelle
2.5k
Fork
772
Merge medio
3g 15h
PR unite (30g)
46

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di github/advisory-database

Tutte le issue di github/advisory-database

Issue simili

Altre issue su Databases

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.