Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Published repository advisories not appearing in the Advisory Database after 10-13 days

Aperta
#9,152 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Da chiarire
Stato di attività
Attiva
Stack tecnologico
github

Direzione di ricerca

Inizia con le query API GET /advisories elencate e le ricerche corrispondenti nella UI web, quindi confronta i quattro advisory del repository con gli advisory di controllo e con il comportamento descritto in #9025. Determina se le voci mancanti sono causate dalle tempistiche della curation, dalle mappature dei pacchetti, dalle richieste CVE o da un altro passaggio di indicizzazione; il lavoro è concluso quando sono state stabilite la causa e l’azione prevista da parte del maintainer.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

A question about how published repository advisories reach this database, with four concrete examples. I may well be misunderstanding the intended flow — happy to be told this is expected.

Four repository advisories I am credited on were published by their maintainers between 4 and 13 August. All four are live and public on their repos. None appear in the Advisory Database.

advisory package ecosystem published
GHSA-x6wm-3hvg-6pqh webdav-server npm 2026-08-04
GHSA-6gvx-vjgp-49x3 url-sheriff npm 2026-08-07
GHSA-pv2m-3wr7-9vp8 is-local-address npm 2026-08-13
GHSA-58r7-5cr4-4ffr tarsafe pip 2026-08-13

All four queries come back empty:

GET /advisories?ecosystem=npm&affects=webdav-server      -> []
GET /advisories?ecosystem=npm&affects=url-sheriff        -> []
GET /advisories?ecosystem=npm&affects=is-local-address   -> []
GET /advisories?ecosystem=pip&affects=tarsafe            -> []

Two controls, to show the query itself is fine:

GET /advisories?ecosystem=npm&affects=extract-zip  -> GHSA-jmr9-qjv8-65gv
GET /advisories?ecosystem=npm&affects=ssrfcheck    -> 3 advisories

Searching the web UI directly (/advisories?query=webdav-server, ?query=tarsafe) also returns only unrelated keyword matches, no advisory for those packages.

It also does not look like a general backlog — repository-sourced advisories published between 14 and 17 August are already present, e.g. GHSA-m44r-7c5h-m6mj, GHSA-ggr8-5vv4-36mx, GHSA-76pc-mqxp-3rq5. The four above are 4 to 13 days older than those.

On each of the four, the advisory form has the package name, ecosystem, affected version range and patched version filled in, so as far as I can tell there is nothing missing that would prevent a package mapping.

Questions
  1. Is there a step the maintainer or reporter needs to take beyond publishing the repository advisory?
  2. Is 10-13 days inside the normal curation window? The docs say every repository advisory is reviewed "for consideration" as a global advisory, which I read as meaning promotion is not automatic — I would just like to understand what makes the difference.
  3. Does requesting a CVE affect whether or when an advisory is curated? Three of the four have a CVE request lodged; GHSA-58r7-5cr4-4ffr (tarsafe) does not, and I would like to know whether that matters so I can advise the maintainer correctly.
Why it matters

Until an advisory is in this database, npm audit, pip audit and Dependabot do not surface it, so people running the affected versions get no signal even though the advisory is fully public. tarsafe alone is around 376k downloads/month and webdav-server around 27k/week.

This is the same shape as an issue I contributed a fix for in #9025, where an advisory existed with an empty affected array and therefore mapped to no package, leaving everything keyed on package mappings silent. I am not claiming that is the cause here — the mappings look populated — but the user-visible effect is identical.

Happy to open separate per-advisory issues instead if that is the preferred format, or to provide anything else useful. Thanks for maintaining this.

Lingua principale
Nessun dato sulla lingua
Stelle
2.5k
Fork
772
Merge medio
3g 15h
PR unite (30g)
46

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di github/advisory-database

Tutte le issue di github/advisory-database

Issue simili

Altre issue su Backend & API Design

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.