Skip to content
This repository has been archived by the owner on Mar 8, 2023. It is now read-only.

Consider using project kb's data #43

Open
sbs2001 opened this issue Sep 24, 2020 · 1 comment
Open

Consider using project kb's data #43

sbs2001 opened this issue Sep 24, 2020 · 1 comment
Labels
enhancement New feature or request p2

Comments

@sbs2001
Copy link
Contributor

sbs2001 commented Sep 24, 2020

Project KB contains manually curated commit links which fix particular CVE. It contains commits which actually rectified "vulnerable code" unlike NVD which many times contains commits which tagged release.

Vulncode-db can leverage project KB's data and provide more examples of real world vulnerable code.

Data is at :

https://github.com/SAP/project-kb/blob/master/MSR2019/dataset/vulas_db_msr2019_release.csv
https://github.com/SAP/project-kb/tree/vulnerability-data/statements

FYI project KB is used by https://github.com/eclipse/steady .

@evonide
Copy link
Contributor

evonide commented Sep 27, 2020

I was unaware of this project this is excellent to know thanks a lot for sharing this!
Currently, we're more focused on completing the contributions review system and addressing all issues in https://github.com/google/vulncode-db/milestone/1 to get a first candidate that accepts community content.

However, we'll certainly look into integrating the linked data into Vulncode-DB, too at some later point in time.

@evonide evonide added enhancement New feature or request p2 labels Sep 27, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request p2
Projects
None yet
Development

No branches or pull requests

2 participants