Skip to content

x/vulndb: track file changes in a commit related to the CVE #49462

@julieqiu

Description

@julieqiu

There are times when a CVE is identified as a Go vulnerability because of the module path, but it is actually not related to Go and no Go files will be updated in the commit. It would be useful to use the GitHub API to check which files actually changed, if a commit URL is available in the reference data section.

For example, see the tensorflow block from CVE-2021-29512 through CVE-2021-29619.

Metadata

Metadata

Assignees

No one assigned

    Labels

    NeedsInvestigationSomeone must examine and confirm this is a valid issue and not a duplicate of an existing one.vulncheck or vulndbIssues for the x/vuln or x/vulndb repo

    Type

    No type

    Projects

    Status

    No status

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions