Skip to content

建议:扩展PoC市场并支持SARIF导出和CNVD集成 #211

Description

@hmkklol

你好 @zan8in

afrog的curated PoC市场是一个独特的优势。建议进一步增强:

建议1:SARIF导出
在curated服务中增加SARIF 2.1.0格式返回:

  • 每次下载PoC时同时获取对应的SARIF规则定义
  • 扫描结果可以直接生成完整的SARIF报告
  • 兼容GitHub/GitLab/DefectDojo

建议2:CNVD自动集成
建立CNVD(国家信息安全漏洞库)自动同步流水线:

  1. 每周从CNVD官网抓取最新漏洞公告
  2. 解析受影响产品和版本
  3. 自动生成afrog PoC模板(基于常见模式)
  4. 提交到curated市场审核
  5. 社区验证后发布

技术实现:

  • CNVD数据抓取(需处理反爬)
  • NLP提取产品名称和版本范围
  • 模板填充(基于已有的同类PoC)

这会让afrog在中文漏洞覆盖方面建立不可替代的优势。

[English Translation / 英文摘要]

Hi maintainers, this issue is a feature / architecture / security suggestion for 14_afrog.
The Chinese text above contains the detailed proposal with technical context and implementation ideas.
In summary: we are requesting the enhancement described above and would be happy to provide PRs or further discussion in either Chinese or English.
Thank you for the excellent work on this project!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions