Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Adding GHSA from non ecosystem software

未关闭
#7,268 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
30/100
Issue 类型
功能
描述清晰度
需要澄清
活跃度
冷清
技术栈
github
领域
database, security

调研方向

从 repository README 中所述的行为入手,并结合项目的 Security 页面审查示例 advisory GHSA-m59c-q9gq-rh2j。issue 未指明源文件或测试;确定非生态系统 advisory 是否属于范围,以及哪项 repository 更改或哪份文档可以定义完成标准。

由索引模型根据 Issue 内容生成。

描述

Hello,

i currently started working with the Github Adivsory Database to track vulnerabilities for packages which are not part of any Ecosystem. For example when using https://github.com/mcu-tools/mcuboot they track their vulnerabilities using Github. But the recorded GHSA for example GHSA-m59c-q9gq-rh2j are not listed in the Database.
While i understand that per Readme this behavior is intended I do not really understand the reason.
For my understanding GHSA are already checked by the maintainer of the project before they are listed on the Security Page of the respective project. So i do not understand the benefit of not listing those vulnerabilities to the Database.

Is there any chance that such vulnerabilities could be added to this database?

Best regards

主要语言
没有语言数据
星标
2.5k
派生
772
平均合并
3 天 15 小时
30 天内合并 PR
46

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/advisory-database 的其他 Issue

查看 github/advisory-database 的全部 Issue

相似的 Issue

更多 Databases Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。