x/vulndb: track file changes in a commit related to the CVE #49462
Labels
NeedsInvestigation
Someone must examine and confirm this is a valid issue and not a duplicate of an existing one.
vulncheck or vulndb
Issues for the x/vuln or x/vulndb repo
Milestone
There are times when a CVE is identified as a Go vulnerability because of the module path, but it is actually not related to Go and no Go files will be updated in the commit. It would be useful to use the GitHub API to check which files actually changed, if a commit URL is available in the reference data section.
For example, see the tensorflow block from CVE-2021-29512 through CVE-2021-29619.
The text was updated successfully, but these errors were encountered: