Skip to content

Collect apache project's machine readable advisories. #314

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
sbs2001 opened this issue Jan 24, 2021 · 0 comments
Open

Collect apache project's machine readable advisories. #314

sbs2001 opened this issue Jan 24, 2021 · 0 comments

Comments

@sbs2001
Copy link
Collaborator

sbs2001 commented Jan 24, 2021

In any case we want to avoid parsing human readable advisories, so to break #100 in smaller manageable parts , we should always parse machine readable advisories if possible.

Apache projects maintain machine readable security advisories at a project level. See for example

https://github.com/apache/syncope/blob/fa82b8266c0c664c49d010d397a9ffb3f6ab4555/src/site/xdoc/security.xml
https://github.com/apache/ofbiz-site/blob/8a3e9fb778858257fd1b930e51059f5a61d2457a/template/page/security.tpl.php
https://github.com/search?q=org%3Aapache+cve&type=code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants