-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add DTSA to vulnid #11302
base: bugfix
Are you sure you want to change the base?
Add DTSA to vulnid #11302
Conversation
DryRun Security SummaryThe pull request updates the configuration files for the DefectDojo application, including a change to the SHA-256 checksum file for the Expand for full summarySummary: The changes in this pull request are focused on updating configuration files for the DefectDojo application. The first change updates the SHA-256 checksum file for the From an application security perspective, the changes do not introduce any immediate security concerns. The update to the checksum file is a routine maintenance task to ensure the integrity of the configuration file, and the addition of new vulnerability URL mappings is an enhancement to the application's functionality. However, it is important to ensure that the new hash value in the checksum file is correct and that the Files Changed:
Code AnalysisWe ran Riskiness🟢 Risk threshold not exceeded. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approved
@manuel-sommer OK, I have to ask, where are you finding all these? None of them surprised me that they exist but I'm super curious if these are being reported by a tool you're using or if you're just searching around to find them. Sorry, my curiosity is getting the better of me. 😄 |
A mixture of both. Multiple of them were reported through tools. I regularly review the findings and from time to time I find vulnids which can't be resolved. Then, I make a PR. Also, to deal with this in future scenarios, I advanced my research for future occurances of other findings. --> e.g. https://linuxsecurity.com/ --> Advisories |
This pull request has conflicts, please resolve those before we can evaluate the pull request. |
Conflicts have been resolved. A maintainer will review the pull request shortly. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry, my curiosity is getting the better of me. 😄
I have been very curious as well 😂 you're quite the detective @manuel-sommer
https://security-tracker.debian.org/tracker/data/missing-epochs --> Search for DTSA