Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Tomcat entry updates

Aperta
#4,590 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
25/100
Tipo di issue
Bug
Chiarezza
Da chiarire
Stato di attività
Ferma
Stack tecnologico
java
Ambito
security

Direzione di ricerca

Inizia esaminando il foglio di calcolo collegato e confrontando le relative mappature dei componenti con i GitHub advisories di riferimento, inclusi GHSA-3p86-xgrq-m6p6 e GHSA-f4qf-m5gf-8jm8. Prima di apportare modifiche, chiarisci con i manutentori di advisory-database come debba essere inviato questo corpus e quali voci rientrino nell’ambito; il lavoro è completato quando gli aggiornamenti accettati identificano i componenti Tomcat interessati anziché il pacchetto aggregato del progetto.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Hello,

I have a spreadsheet with a large number of Tomcat advisory updates (this sheet is not current with the latest Tomcat vulnerabilities)
https://docs.google.com/spreadsheets/d/1b8XqUEK1PuOfTjm1jj-YSIoQa92A7uwjVfF06kd4bXg/edit?gid=0#gid=0

Many GitHub advisories for tomcat reference the package org.apache.tomcat:tomcat, which is not an installable jar. For example
https://github.com/advisories/GHSA-3p86-xgrq-m6p6

Vulnerability scanners should be detecting specific components of the Tomcat project rather than the project itself, and vulnerabilities affect specific Tomcat jars, not all Tomcat jars.

There are some GitHub Tomcat advisories that do capture the specific components that a vulnerability affects
https://github.com/advisories/GHSA-f4qf-m5gf-8jm8

In the spreadsheet I have identified the Tomcat component(s) affected by the given vulnerabilities in column D. Some of the vulnerabilities couldn't be figured out, or are documentation or example updates. I left them in for posterity.

I have a few questions about how to submit this large corpus of updates. I would like to work with the GitHub team to minimize friction. I'm very open to suggestions. I can submit one big PR, many small PRs. I'm happy to trickle them in if that's easier. Whatever works best for the GitHub team.

Lingua principale
Nessun dato sulla lingua
Stelle
2.5k
Fork
772
Merge medio
3g 15h
PR unite (30g)
46

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di github/advisory-database

Tutte le issue di github/advisory-database

Issue simili

Altre issue su Security

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.