Skip to content

Commit 21df09b

Browse files
authored
Merge pull request #3145 from CVEProject/test
update main with Test
2 parents 9cb6c6b + f36aa3f commit 21df09b

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

47 files changed

+365
-417
lines changed

src/assets/data/CNAsList.json

Lines changed: 39 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -809,7 +809,7 @@
809809
"shortName": "Axis",
810810
"cnaID": "CNA-2021-0014",
811811
"organizationName": "Axis Communications AB",
812-
"scope": "All products of Axis Communications AB including end-of-life/end-of-service products",
812+
"scope": "All products of Axis Communications AB and 2N including end-of-life/end-of-service products",
813813
"contact": [
814814
{
815815
"email": [
@@ -2668,7 +2668,7 @@
26682668
"shortName": "fedora",
26692669
"cnaID": "CNA-2017-0021",
26702670
"organizationName": "Fedora Project",
2671-
"scope": "Vulnerabilities in open-source projects affecting the Fedora Project, that are not covered by a more specific CNA. CVEs can be assigned to vulnerabilities affecting end-of-life or unsupported releases by the Fedora Project",
2671+
"scope": "Vulnerabilities in open source projects affecting the Fedora Project, that are not covered by a more specific CNA. CVEs can be assigned to vulnerabilities affecting end-of-life or unsupported releases by the Fedora Project",
26722672
"contact": [
26732673
{
26742674
"email": [],
@@ -3817,7 +3817,7 @@
38173817
"shortName": "hp",
38183818
"cnaID": "CNA-2009-0003",
38193819
"organizationName": "HP Inc.",
3820-
"scope": "HP Inc. issues only",
3820+
"scope": "Issues with any HP-branded product, including computing software and hardware, imaging and printing, as well as HyperX, Teradici, Poly, and Plantronics branded devices",
38213821
"contact": [
38223822
{
38233823
"email": [
@@ -6806,7 +6806,7 @@
68066806
"advisories": [
68076807
{
68086808
"label": "Advisories",
6809-
"url": "https://www.php.net/ChangeLog-7.php"
6809+
"url": "https://www.php.net/ChangeLog-8.php"
68106810
}
68116811
]
68126812
},
@@ -6837,7 +6837,7 @@
68376837
{
68386838
"shortName": "Perforce",
68396839
"cnaID": "CNA-2016-0023",
6840-
"organizationName": "Perforce (formerly Puppet)",
6840+
"organizationName": "Perforce",
68416841
"scope": "All Perforce products",
68426842
"contact": [
68436843
{
@@ -7065,7 +7065,7 @@
70657065
"shortName": "redhat",
70667066
"cnaID": "CNA-2005-0006",
70677067
"organizationName": "Red Hat, Inc.",
7068-
"scope": "<strong>Root Scope:</strong> The Red Hat Root’s scope includes the open-source community. Any open-source organizations that prefer Red Hat as their Root; organizations are free to choose another Root if it suits them better<br/><strong>CNA Scope:</strong> Vulnerabilities in open-source projects affecting Red Hat software that are not covered by a more specific CNA. CVEs can be assigned to vulnerabilities affecting end-of-life or unsupported Red Hat software",
7068+
"scope": "<strong>Root Scope:</strong> The Red Hat Root’s scope includes the open source community. Any open source organizations that prefer Red Hat as their Root; organizations are free to choose another Root if it suits them better<br/><strong>CNA Scope:</strong> Vulnerabilities in open source projects affecting Red Hat software that are not covered by a more specific CNA. CVEs can be assigned to vulnerabilities affecting end-of-life or unsupported Red Hat software",
70697069
"contact": [
70707070
{
70717071
"email": [
@@ -8929,23 +8929,40 @@
89298929
"emailAddr": "[email protected]"
89308930
}
89318931
],
8932-
"contact": [],
8932+
"contact": [
8933+
{
8934+
"label": "Report a Vulnerability (Turkish)",
8935+
"language": "Turkish",
8936+
"url": "https://www.usom.gov.tr/zafiyet"
8937+
},
8938+
{
8939+
"label": "Report a Vulnerability (English)",
8940+
"language": "English",
8941+
"url": "https://www.usom.gov.tr/en/vulnerability"
8942+
}
8943+
],
89338944
"form": []
89348945
}
89358946
],
89368947
"disclosurePolicy": [
89378948
{
8938-
"label": "Policy",
8939-
"language": "",
8940-
"url": "https://www.usom.gov.tr/en"
8949+
"label": "Policy (Turkish)",
8950+
"language": "Turkish",
8951+
"url": "https://www.usom.gov.tr/zafiyet-bildirim-politikasi"
8952+
},
8953+
{
8954+
"label": "Policy (English)",
8955+
"language": "English",
8956+
"url": "https://www.usom.gov.tr/en/vulnerability-disclosure-policy"
89418957
}
89428958
],
89438959
"securityAdvisories": {
89448960
"alerts": [],
89458961
"advisories": [
89468962
{
8947-
"label": "Advisories",
8948-
"url": "https://www.usom.gov.tr/tehdit.html"
8963+
"label": "Advisories (Turkish)",
8964+
"language": "Turkish",
8965+
"url": "https://www.usom.gov.tr/bildirim"
89498966
}
89508967
]
89518968
},
@@ -9102,7 +9119,7 @@
91029119
"shortName": "Vaadin",
91039120
"cnaID": "CNA-2021-0015",
91049121
"organizationName": "Vaadin Ltd.",
9105-
"scope": "All Vaadin products and supported open-source projects hosted at <a href='https://github.com/vaadin' target='_blank'>https://github.com/vaadin</a>",
9122+
"scope": "All Vaadin products and supported open source projects hosted at <a href='https://github.com/vaadin' target='_blank'>https://github.com/vaadin</a>",
91069123
"contact": [
91079124
{
91089125
"email": [
@@ -14699,7 +14716,7 @@
1469914716
"shortName": "Docker",
1470014717
"cnaID": "CNA-2022-0050",
1470114718
"organizationName": "Docker Inc.",
14702-
"scope": "All Docker products, including Docker Desktop and Docker Hub, as well as Docker maintained open-source projects",
14719+
"scope": "All Docker products, including Docker Desktop and Docker Hub, as well as Docker maintained open source projects",
1470314720
"contact": [
1470414721
{
1470514722
"email": [
@@ -14997,7 +15014,7 @@
1499715014
"shortName": "dotCMS",
1499815015
"cnaID": "CNA-2023-0001",
1499915016
"organizationName": "dotCMS LLC",
15000-
"scope": "All dotCMS product services including the vulnerabilities reported in our open-source core located at <a href='https://github.com/dotCMS/core' target='_blank'>https://github.com/dotCMS/core</a>",
15017+
"scope": "All dotCMS product services including the vulnerabilities reported in our open source core located at <a href='https://github.com/dotCMS/core' target='_blank'>https://github.com/dotCMS/core</a>",
1500115018
"contact": [
1500215019
{
1500315020
"email": [
@@ -15059,7 +15076,7 @@
1505915076
"shortName": "DHIS2",
1506015077
"cnaID": "CNA-2023-0002",
1506115078
"organizationName": "The HISP Centre at the University of Oslo",
15062-
"scope": "Security issues in <a href='https://github.com/dhis2' target='_blank'>DHIS2</a> open-source web and mobile software applications",
15079+
"scope": "Security issues in <a href='https://github.com/dhis2' target='_blank'>DHIS2</a> open source web and mobile software applications",
1506315080
"contact": [
1506415081
{
1506515082
"email": [
@@ -16251,7 +16268,7 @@
1625116268
"shortName": "Ribose",
1625216269
"cnaID": "CNA-2023-0023",
1625316270
"organizationName": "Ribose Limited",
16254-
"scope": "All Ribose products and services, including open-source projects, supported products, and end-of-life/end-of-service products",
16271+
"scope": "All Ribose products and services, including open source projects, supported products, and end-of-life/end-of-service products",
1625516272
"contact": [
1625616273
{
1625716274
"email": [
@@ -16533,7 +16550,7 @@
1653316550
"shortName": "IoT83",
1653416551
"cnaID": "CNA-2023-0028",
1653516552
"organizationName": "IoT83 Ltd",
16536-
"scope": "Vulnerabilities in IoT83 product(s), services, and components only. Third-party, open-source components used in IoT83 product(s), services, and components are not in scope",
16553+
"scope": "Vulnerabilities in IoT83 product(s), services, and components only. Third-party, open source components used in IoT83 product(s), services, and components are not in scope",
1653716554
"contact": [
1653816555
{
1653916556
"email": [
@@ -16899,7 +16916,7 @@
1689916916
"shortName": "samsung.tv_appliance",
1690016917
"cnaID": "CNA-2023-0034",
1690116918
"organizationName": "Samsung TV & Appliance",
16902-
"scope": "Samsung TV &amp; Appliance products, Samsung-owned open-source projects listed on <a href='https://github.com/Samsung/' target='_blank'>https://github.com/Samsung/</a>, as well as vulnerabilities in third-party software discovered by Samsung that are not in another CNA’s scope. Vulnerabilities affecting end-of-life/end-of-service products are in scope. The following categories of Samsung Products are in scope: Internet-connected home appliances, B2C product (smart TV, smart monitor, soundbar, and projector), and B2B products (digital signage, interactive display, and kiosk)",
16919+
"scope": "Samsung TV &amp; Appliance products, Samsung-owned open source projects listed on <a href='https://github.com/Samsung/' target='_blank'>https://github.com/Samsung/</a>, as well as vulnerabilities in third-party software discovered by Samsung that are not in another CNA’s scope. Vulnerabilities affecting end-of-life/end-of-service products are in scope. The following categories of Samsung Products are in scope: Internet-connected home appliances, B2C product (smart TV, smart monitor, soundbar, and projector), and B2B products (digital signage, interactive display, and kiosk)",
1690316920
"contact": [
1690416921
{
1690516922
"email": [
@@ -19436,7 +19453,7 @@
1943619453
"shortName": "Checkmarx",
1943719454
"cnaID": "CNA-2023-0078",
1943819455
"organizationName": "Checkmarx",
19439-
"scope": "Vulnerabilities in Checkmarx products and open-source vulnerabilities discovered by, or reported to, Checkmarx, that are not in another CNA’s scope",
19456+
"scope": "Vulnerabilities in Checkmarx products and open source vulnerabilities discovered by, or reported to, Checkmarx, that are not in another CNA’s scope",
1944019457
"contact": [
1944119458
{
1944219459
"email": [
@@ -19719,7 +19736,7 @@
1971919736
"shortName": "EDB",
1972019737
"cnaID": "CNA-2023-0083",
1972119738
"organizationName": "EnterpriseDB Corporation",
19722-
"scope": "All EnterpriseDB products and vulnerabilities identified in open-source libraries used by EnterpriseDB products unless covered by another CNA’s scope",
19739+
"scope": "All EnterpriseDB products and vulnerabilities identified in open source libraries used by EnterpriseDB products unless covered by another CNA’s scope",
1972319740
"contact": [
1972419741
{
1972519742
"email": [
@@ -23203,7 +23220,7 @@
2320323220
"shortName": "seal",
2320423221
"cnaID": "CNA-2024-0060",
2320523222
"organizationName": "Seal Security",
23206-
"scope": "Vulnerabilities in Seal products or services and vulnerabilities discovered in open-source libraries unless covered by the scope of another CNA",
23223+
"scope": "Vulnerabilities in Seal products or services and vulnerabilities discovered in open source libraries unless covered by the scope of another CNA",
2320723224
"contact": [
2320823225
{
2320923226
"email": [

src/assets/data/glossaryEntries.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -117,7 +117,7 @@
117117
"id": "glossarySupplier",
118118
"term": "Supplier",
119119
"termLink": "/ResourcesSupport/Glossary?activeTerm=glossarySupplier",
120-
"definition": "The entity that develops, maintains, or provides a product regardless of whether the product is an open-source project or a proprietary product. A supplier is typically responsible for and capable of investigating vulnerability reports and developing fixes or mitigations for vulnerabilities. “Supplier” is used broadly and includes common terms such as vendor, producer, developer, maintainer, author, owner, manufacturer, and provider."
120+
"definition": "The entity that develops, maintains, or provides a product regardless of whether the product is an open source project or a proprietary product. A supplier is typically responsible for and capable of investigating vulnerability reports and developing fixes or mitigations for vulnerabilities. “Supplier” is used broadly and includes common terms such as vendor, producer, developer, maintainer, author, owner, manufacturer, and provider."
121121
},
122122
{
123123
"id": "glossaryTags",

src/assets/data/metrics.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -789,11 +789,11 @@
789789
"data": [
790790
{
791791
"heading": "All CNAs",
792-
"percentage": "81"
792+
"percentage": "83"
793793
},
794794
{
795795
"heading": "CNA-LRs",
796-
"percentage": "19"
796+
"percentage": "17"
797797
}
798798
]
799799
},

0 commit comments

Comments
 (0)