You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fedcode-next: Extract fix commits from pull requests and issues body or comments in search for CVE-related messages #2002
Implement a pipeline that extracts fix commits from pull requests, issue descriptions, and comments.
The pipeline should search for vulnerability-related messages and security fix indicators using, for example, the GitHub or GitLab API.
This is done, now we can collect issues and PRs in Github and Gitlab. We have a new project named vulnerablecode-vcs-collector at https://github.com/aboutcode-data/vulnerablecode-vcs-collector that is designed to collect fix commits from VCS histories
The current implementation works from hardcoded list of packages. The future improvements will drive that directly from PURLs collected in a CVE or driven from the larger PurlDB. These future improvements are tracked in a separate issue:
Implement a pipeline that extracts fix commits from pull requests, issue descriptions, and comments.
The pipeline should search for vulnerability-related messages and security fix indicators using, for example, the GitHub or GitLab API.