-
Notifications
You must be signed in to change notification settings - Fork 179
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
idea: CVE linkages #431
Comments
Sure, I've had this idea from beginning (#15). I've investigated it couple of times and it turns out to not be that straightforward. CVEs don't usually contain usable package names and use CPE instead. I don't see a way to map CPE to metapackages for now. I don't remember seeing CPE info in any package system apart from FreeBSD, it should be specially extracted from there. We could use distro-specific vulnerability reports as these do contain usable names. There are a lot of these available, for instance: However there are problems as well:
|
Being implemented in #15. |
Would it be possible to link to CVE reports for a given version of a package? Could be an extremely valuable resource.
The text was updated successfully, but these errors were encountered: