Skip to content

RubySec numbering system #224

@mveytsman

Description

@mveytsman

We should stop relying on osvdb and cve ids as canonical identifiers as they may not be always present, as in the case where we get a vuln before it's in either db.

  • Add a new field to the schema, rubysec-id
  • Come up with numbering scheme. My suggestion is to model after CVE, ala RUBYSEC-2016-00001
  • Add a rubysec-ids to past vulns in the database.
  • Come up with policy for generating new id numbes are vulns are added. This should be done by the person with commit bit who's accepting the PR.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions