-
-
Notifications
You must be signed in to change notification settings - Fork 236
Closed
Description
The commit that fixed the vulnerability should also be included in the information provided. Anything that can lead to a diff is valuable. This includes links to commits, pull requests and issues.
As suggested by @pombredanne we can use the specification described here, which supports referencing locations in Git, Mercurial, Subversion and Bazaar. A new field named vcs_url
can be included for each vulnerability.
The following are some example of links found on NVD, usually reported with the Patch tag:
Commits
Lead to diff
- https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=3890db36665dbff4c415b0b0dc5c8d53b2850870
- python/cpython@fbf648e
- https://www.mercurial-scm.org/repo/hg/rev/1acfc35d478c
Pull Requests
Lead to Merge Commit --> diff
Issues
Lead to PR --> Merge Commit --> diff
Others
Extracting diff if present
Sources of commit links
singh1114 and pombredanne
Metadata
Metadata
Assignees
Type
Projects
Status
Validated