-
- Notifications
You must be signed in to change notification settings - Fork 255
Open
Labels
Description
We should extract unpublished vulnerabilities from commit histories and issue trackers
- Parse issues and trackers such as github issues. See Process unstructured data sources #251
- Parse CHANGELOGs. See Parse CHANGELOGs to discover new Vulnerabilities #233 and https://github.com/pyupio/changelogs/
- Parse Git commit messages
- To include fix commits VCIO-next: Add support to track fix commits: Include commits and patches that fix a vulnerability #207
- To find new or existing vulnerabilities
These are valuable information and we can search for CVE and security-related keywords and track these in a curation queue. And eventually submit these as NVD CVEs.
See also:
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
In progress