Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability data for maven-security-versions #10

Open
nasifimtiazohi opened this issue Dec 10, 2020 · 0 comments
Open

Vulnerability data for maven-security-versions #10

nasifimtiazohi opened this issue Dec 10, 2020 · 0 comments

Comments

@nasifimtiazohi
Copy link

Hi,

I am a PhD Student at NC State University. As part of our research, we are evaluating the existing tools that detect vulnerable dependencies. We have observed that the tools’ result can differ based on the strength of its vulnerability database. For our research, we are hoping to understand more on how tools like maven-security-versions maintain its vulnerability database. We’d be grateful if we get some responses for the below questions.

  1. What are your sources for vulnerability data, e.g. NVD, OSS Index?
  2. Do you have any process to discover open source vulnerabilities by yourselves, e.g. through monitoring bug repositories? If yes, is it possible to share with us a high level explanation of what you do?
  3. When collecting vulnerability data from third-party databases (e.g. NVD), do you perform any curation and/or correction, e.g. discarding debated CVEs or correcting the affected version range? If yes, is it possible to share with us a high level explanation of what you do?

Thanks,
Nasif

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant