-
-
Notifications
You must be signed in to change notification settings - Fork 626
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Include CWE mappings for all bandit issues #612
Comments
I have created a PR that adds CWE mappings for all bandit issues and changes the formatters accordingly: #613 |
Please reference this feature in your PR |
I'd like to also see a parameter in the metadata for a link to the http://cwe.mitre.org/ site with the referenced ID. |
Thanks again @ericwb. I addressed your comments in the PR 👍 |
Hello Team, Is this enhancement already done ? Can someone help me on this? |
Is your feature request related to a problem? Please describe.
The internal vulnerability identifiers/issues used by bandit cannot be mapped to commonly used vulnerability metrics such as CWE. Some environments may require CWEs to be used as a standard for categorizing vulnerabilities. In addition, CWE mappings are very useful to consolidate vulnerability reports produced by different tools.
Describe the solution you'd like
Every vulnerability should get assigned a CWE identifier.
Describe alternatives you've considered
Additional context
The text was updated successfully, but these errors were encountered: