rustsec / advisory-db

Security advisory database for Rust crates published through crates.io
https://rustsec.org
Other
900 stars 351 forks source link

Import missing advisories from GitHub advisories #1711

Open amousset opened 1 year ago

amousset commented 1 year ago

Currently 92 missing advisories:

using https://github.com/rustsec/rustsec/pull/656. BTW it also shows problems in crates names used in some GitHub advisories:

Crate names ["bottlerocket/update-operator"] in GHSA-j79x-vvgm-w73w advisory not matching existing advisory RUSTSEC-2023-0009, skipping
Crate names ["bottlerocket/update-operator"] in GHSA-j859-pmrq-9q6c advisory not matching existing advisory RUSTSEC-2023-0007, skipping
Crate names ["Tauri"] in GHSA-q9wv-22m9-vhqh advisory not matching existing advisory RUSTSEC-2022-0091, skipping
Crate names ["bottlerocket/update-operator"] in GHSA-3wxx-jxwc-mg39 advisory not matching existing advisory RUSTSEC-2023-0010, skipping
Unknown crate bottlerocket/update-operator in GHSA-pj34-fpw3-83qj advisory, skipping
Crate names ["mdBook"] in GHSA-gx5w-rrhp-f436 advisory not matching existing advisory RUSTSEC-2021-0001, skipping
Crate names ["compu-brotli-sys"] in GHSA-5v8v-66v8-mwm7 advisory not matching existing advisory RUSTSEC-2021-0131, skipping
Unknown crate bottlerocket/update-operator in GHSA-qf87-q4gg-cg43 advisory, skipping
amousset commented 1 year ago

I'll treat them by descending chronological order.