Open
Description
We are missing crucial information contained inside AffectedPackage
in Advisory
model. We might need a model specifically for AffectedPackage
so that we may create relations to vulnerabilities and possibly packages based on version ranges.
(via: https://github.com/nexB/vulnerablecode/wiki/WeeklyMeetings#meeting-on-tuesday-2022-05-03-at-1000-utc)