Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Picky change to example justification in the spec
I feel like the statement > The vulnerable code was removed with a custom patch fits `vulnerable_code_not_present`: > The vulnerable component is included in artifact, but the vulnerable code is not present. Typically, this case occurs when source code is configured or built in a way that excluded the vulnerable code. better than `component_not_present`: > The product is not affected by the vulnerability because the component is not included. The status justification may be used to preemptively inform product users who are seeking to understand a vulnerability that is widespread, receiving a lot of attention, or is in similar products. The statement specifically states "vulnerable *code* was removed" via a patch. Rather than the whole component being removed. Signed-off-by: Gareth Rushgrove <[email protected]>
- Loading branch information