Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Repo specific advisories with CVE IDs don't make it into the global set

オープン
#3,266 コメント 3 件 リアクション 5 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
30/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
github, grafana

調査の方向性

Grafana の advisory GHSA-2x6g-h2hg-rq84 から始め、割り当てられた CVE-2022-39306 と GitHub Advisory Database の検索結果を比較します。CVE IDs を持つリポジトリ固有の advisory がどのように扱われるかを追跡し、その CVE がグローバルデータベースに存在する時点で issue が解決済みとみなします。

索引モデルが issue の本文から書いたものです。

説明

It looks like if a repo has an advisory that was not marked to enter the global database, and that advisory is assigned a CVE ID, the CVE ID in question is not present in the GitHub Advisory Database.

I feel like I'm not explaining this well, so I have an example.

This Grafana advisory
https://github.com/grafana/grafana/security/advisories/GHSA-2x6g-h2hg-rq84

Has been assigned CVE-2022-39306

If you search the GitHub advisory database, that ID doesn't show up.

It is nice to use the GitHub database, even for unreviewed IDs, because it's vastly more complete and accurate for supported ecosystems than other sources. Incomplete CVE data means multiple data sources must be queried to get a full picture of which IDs exist.

Related is https://github.com/github/advisory-database/issues/2963 where I suggest allowing community contributions for non supported ecosystems, it would be a service to the world to have a public place to store useful details uncovered during investigations

主要言語
言語のデータがありません
スター
2.5k
フォーク
772
平均マージ
3日 15時間
マージ済み PR(30日)
46

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/advisory-database のほかの issue

github/advisory-database の issue をすべて見る

似ている issue

Databases の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。