Skip to content

Added liferay advisories #1774

Closed
Dedsec0098 wants to merge 2595 commits intoaboutcode-org:mainfrom
Dedsec0098:add-liferay-advisories
Closed

Added liferay advisories #1774
Dedsec0098 wants to merge 2595 commits intoaboutcode-org:mainfrom
Dedsec0098:add-liferay-advisories

Conversation

@Dedsec0098
Copy link

@Dedsec0098 Dedsec0098 commented Feb 8, 2025

Fix #1410

  • Added liferay advisories by adding liferay.py in the importers

  • Updated init.py to register my importer

Signed-off-by: Shrish Mishra shrish409@gmail.com

pombredanne and others added 30 commits September 12, 2024 15:10
…ort-command

Improve export commandSigned-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: ziadhany <ziadhany2016@gmail.com>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Fix typo in Kev requests importSigned-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Tushar Goel <tushar.goel.dav@gmail.com>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Prepare for release v34.0.1Signed-off-by: Shrish Mishra shrish409@gmail.com
- Use the same major version for upload-artifact and download-artifact

Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Bump upload-artifact to v4Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
- For now pipeline_id should be module name of pipeline

Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
- Update the created_by field on old advisory to new pipeline_id

Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
…-pipeline

Migrate Npm importer to aboutcode pipelineSigned-off-by: Shrish Mishra shrish409@gmail.com
* Instead return None if we cannot get proper fixed or affected version

Reference: aboutcode-org#1214
Signed-off-by: Jan-Niclas Struewer <j.n.struewer@gmail.com>
Signed-off-by: Philippe Ombredanne <pombredanne@nexb.com>Signed-off-by: Shrish Mishra shrish409@gmail.com
…regex

Use correct regex for CVESigned-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
…er-pipeline

Migrate Nginx importer to aboutcode pipelineSigned-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
…ter-pipeline

Migrate GitLab importer to aboutcode pipelineSigned-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
TG1999 and others added 11 commits January 13, 2025 20:05
Signed-off-by: Tushar Goel <tushar.goel.dav@gmail.com>
Signed-off-by: Shrish Mishra shrish409@gmail.com
…pipeline

Add Pipeline to add missing CVSSV3.1 scoresSigned-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Shrish Mishra shrish409@gmail.com
…description-release

Add description and reference to the latest release on the homepageSigned-off-by: Shrish Mishra shrish409@gmail.com
Use proper apk package type for AlpineSigned-off-by: Shrish Mishra shrish409@gmail.com
@Dedsec0098
Copy link
Author

@pombredanne I have added the liferay advisories, please review it and let me know if any further changes are required.

@Rishi-source
Copy link

Hi @Dedsec0098 , I Would like to suggest you some changes which can make you liferay importer even more reliable as well as functional. Please feel free to correct me if I am wrong somewhere :)

Some contributing advices

  • Please make your pull request particular as per you pull request title I can see that you have added NVD Anchor pipeline as well in the same PR in which you have added liferay pipeline.
  • Please Add a Signed off by in your PR description and for more information please consider to read Contributing Guidelines.
    OPTIONAL - If possible then consider making the tests for your pipeline which can run and check the workingness of the code when workflows are applied.

@Dedsec0098
Copy link
Author

Dedsec0098 commented Feb 8, 2025

Hey @Rishi-source Thanks a lot for letting me know!!
Actually I have raise a different PR for NVD Anchore Pipeline and that one is also under review altho I have made a separate branch for both the PRs but due to unmerged PR those changed files are also shown here.

@Rishi-source
Copy link

Do not worry about your unmerged PR while making a new PRs if both the pull req. have unrelated changes (changes which are not conflicting) then github will provide a update branch option whenever new changes are merged.

@pombredanne
Copy link
Member

@Dedsec0098 Thanks, if you could keep each PR separate, that would be much better. This is hard to merge otherwise.

@pombredanne
Copy link
Member

@Dedsec0098 Dedsec0098 marked this pull request as draft February 13, 2025 05:25
@Dedsec0098
Copy link
Author

Sure @pombredanne, I will make the necessary changes

@Dedsec0098 Dedsec0098 force-pushed the add-liferay-advisories branch from 66b5626 to 64b3efd Compare February 15, 2025 09:35
@Dedsec0098 Dedsec0098 marked this pull request as ready for review February 15, 2025 09:50
@Dedsec0098
Copy link
Author

Dedsec0098 commented Feb 15, 2025

Hey @pombredanne I have separated this PR and also updated the PR message
Please let me know if any further changes are to be maid.

@Dedsec0098 Dedsec0098 changed the title Fix #1410 - Added liferay advisories Added liferay advisories - Fix #1410 Feb 15, 2025
@Dedsec0098 Dedsec0098 changed the title Added liferay advisories - Fix #1410 Added liferay advisories Mar 1, 2025
Signed-off-by: Shrish0098 <shrish409@gmail.com>
@Dedsec0098 Dedsec0098 closed this Mar 1, 2025
@Dedsec0098 Dedsec0098 force-pushed the add-liferay-advisories branch from bf13f7e to 5f0b3cb Compare March 1, 2025 18:29
@Dedsec0098 Dedsec0098 deleted the add-liferay-advisories branch March 1, 2025 18:30
@Dedsec0098 Dedsec0098 restored the add-liferay-advisories branch March 1, 2025 18:31
@Dedsec0098 Dedsec0098 deleted the add-liferay-advisories branch March 1, 2025 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add Liferay advisories

7 participants