cve-bin-tool icon indicating copy to clipboard operation
cve-bin-tool copied to clipboard

Checker wishlist (to convert to individual issues)

Open terriko opened this issue 4 years ago • 3 comments

During our GSoC meeting this week, I mentioned to @SaurabhK122 that we had an older wishlist, but I hadn't updated it lately to see how much of it we covered. Here's the list with the stuff we've covered already removed:

Component Issue if filed (mouse over for status) 
linux_kernel https://github.com/intel/cve-bin-tool/issues/223
v8  
coreclr  
tcpdump    
freetype    #1043
qt    #1044
perl https://github.com/intel/cve-bin-tool/issues/226
jre   #1038  
libsndfile    
libxslt   #978
pcre  
openjpeg   #976
dnsmasq  
jasper  
libxkbcommon    #1041
confluence    
guava  
junit   
libexif https://github.com/intel/cve-bin-tool/issues/117
flexnet_publisher    
libvorbis    
lucene  
lcms  
wpa_supplicant    
libevent   #977
libx11  #1041
stagefright  
Calendar  
commons-compress   #1040
patch  
sql_server  #714 (may be hard)
System.Net.Http https://github.com/intel/cve-bin-tool/issues/35
httpcomponents-client    
harfbuzz https://github.com/intel/cve-bin-tool/issues/37
gdb    
jetty https://github.com/intel/cve-bin-tool/issues/36
qcms    
dom4j  
rsync https://github.com/intel/cve-bin-tool/issues/29
ppp ihttps://github.com/intel/cve-bin-tool/issues/34
shadow  Debian Shadow?

terriko avatar May 28 '20 20:05 terriko

Everything that's been merged is now removed from the table above. I'm going to cherry pick a few more to add as potential new contributor issues and I'll update this list as I do. Anyone else should feel free to do the same and just link to this issue (#709) so they'll show up as related to this list.

terriko avatar May 28 '20 20:05 terriko

Once all individual checkers on this list have been filed as separate issues, this can be closed.

terriko avatar May 28 '20 21:05 terriko

Updating this today to remove some fixed issues and file a few new ones

terriko avatar Jan 21 '21 22:01 terriko

Can I work on this issue?

singh-anushka avatar Jan 05 '23 18:01 singh-anushka

Updated with links from #2494 -- thanks @singh-anushka !

terriko avatar Jan 06 '23 00:01 terriko

I've replaced the section at the top with a list so you can see the statuses and removed ones that were merged. Here's old table just in case we want a record of what was completed although I suppose it's already recorded via commits/issues/the code.

Component Issue if filed (mouse over for status) 
linux_kernel https://github.com/intel/cve-bin-tool/issues/223
v8   #1453
coreclr  
tcpdump    #850, merged
freetype    #1043
qt    #1044
perl https://github.com/intel/cve-bin-tool/issues/226
jre   #1038  
libsndfile   #1492
libxslt   #978
pcre  
openjpeg   #976
dnsmasq  #2042
jasper   #519 and #521
libxkbcommon    #1041
confluence    
guava  
junit   #1707
libexif https://github.com/intel/cve-bin-tool/issues/117
flexnet_publisher    
libvorbis   #2027 , merged
lucene  
lcms  
wpa_supplicant    #1134, merged but blocked
libevent   #977
libx11  #1041
stagefright  
Calendar  
commons-compress   #1040
patch  #2044, merged
sql_server  #714 (may be hard)
System.Net.Http https://github.com/intel/cve-bin-tool/issues/35
httpcomponents-client    
harfbuzz https://github.com/intel/cve-bin-tool/issues/37
gdb    
jetty https://github.com/intel/cve-bin-tool/issues/36
qcms    
dom4j  
rsync https://github.com/intel/cve-bin-tool/issues/29
ppp ihttps://github.com/intel/cve-bin-tool/issues/34
shadow  Debian Shadow?

terriko avatar Jan 06 '23 00:01 terriko

gdb done with 9c788f92b03f68a2296a31b98e1e1debe2e008c7

ffontaine avatar Jan 31 '23 14:01 ffontaine

Thanks, I've removed gdb from the list above.

terriko avatar Jan 31 '23 23:01 terriko

Are there issues here still open? I would like to work on it :)

yashviradia avatar Jun 28 '23 06:06 yashviradia

@yashviradia I think some of these are still available, but it's been a while since the list was updated, so you should check https://github.com/intel/cve-bin-tool/tree/main/cve_bin_tool/checkers before trying to work on any of these. You might also enjoy looking through #2761 if you can;t find anything on this list that looks doable (it's entirely possible that most of what's left here is left because it's really hard to do).

terriko avatar Jun 29 '23 18:06 terriko

This wishlist is getting pretty old and I think we've done most of the tractable things on it, so I'm going to go ahead and close the issue.

terriko avatar Apr 17 '24 21:04 terriko