Skip to content

fedcode-next: Extract unpublished vulnerabilities from commit histories and trackers #1129

Description

@pombredanne

We should extract unpublished vulnerabilities from commit histories and issue trackers

Beyond, that we could:

These are valuable information and we can search for CVE and security-related keywords and track these in a curation queue. And eventually submit these as NVD CVEs.

See also:

Activity

  1. self-assigned this
    on Aug 30, 2025
  2. moved this to In progress in 00-AboutCodePlanneron Nov 3, 2025
  3. pombredanne commented on Feb 12, 2026

    @pombredanne
    MemberAuthor

    We now can parse Git commit messages for vulnerabilities.

    This is an initial script to parse Git commit messages that can be easily integrated with our model. The script takes a Git repository as input, parses all commits, and returns the CVEs along with their corresponding fixed commits.

    We now have a "collect_fix_commits" importer, and we import fix commits from at least these repositories:

  4. changed the title [-]Extract unpublished vulnerabilities from commit histories and trackers[/-] [+]fedcode-next: Extract unpublished vulnerabilities from commit histories and trackers[/+] on Mar 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions