Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrate Morefixes dataset into GHAD #4611

Closed
JafarAkhondali opened this issue Jul 16, 2024 · 3 comments
Closed

Integrate Morefixes dataset into GHAD #4611

JafarAkhondali opened this issue Jul 16, 2024 · 3 comments

Comments

@JafarAkhondali
Copy link

Hello,
I've combined GHAD and NIST in my research paper and combined other tools to create the largest CVEs matched with their fix commits. Ofcourse there are limitations, but I believe it might be a good idea to merge Morefixes dataset into this repository. You can find all related data and the link to the paper here: https://github.com/JafarAkhondali/morefixes
Let me know what do you think

@darakian
Copy link
Contributor

Hoi en dank je wel voor de referentie :)

Interesting paper indeed and I'm really happy that our database could aid in your research! That said, we're not going to blanket import your database without review. It looks like most of your paper concerns projects which are out of scope for us
https://github.com/github/advisory-database?tab=readme-ov-file#supported-ecosystems
But if you'd like to make PRs to add fix commits or to otherwise improve anything that is in scope that would be amazing 👍

@JafarAkhondali
Copy link
Author

Hallo en bedankt voor het antwoorden :)

We used ecosystems such as (npm, pypi, Go, etc) to find repository addresses. It's possible to use https://deps.dev/ service to trace a GitHub repository back to the package name. Of course, you also need to review them. But I was looking for a semi-automated way. For example, I can first send some pull requests that are expected to have the same quality if we do it automatically, and then if everything works fine, we can convert go with larger chunks of changes.
Anyway, if there is no one from your team to help with the integration, I'll start contributing but not soon.

@darakian
Copy link
Contributor

The automation is just PRs :)
If I can make one ask, please just rate limit them as we review everything manually 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants