Reference collection
Software vulnerabilities, as disclosed
Disclosed weaknesses in software and the systems built on it, held as records — the disclosure itself, not the coverage of it.
What’s on this shelf
Filed beside the repository and question-and-answer collections, so a disclosure and the code and discussion around it can be read together.
What one record is
One disclosed weakness, filed as a record rather than as an article reporting it.
Every record also keeps the address it was read from, so any answer built on it can be followed back to the original.
What you can do with it
What this collection is kept for.
Search by what is affected
Describe the component or the behaviour in plain words and reach the disclosures that concern it.
Read it beside the code
Repositories and developer discussion sit on neighbouring shelves, so a disclosure and its context arrive together.
Follow it back
Every record keeps the address it was read from, so a disclosure can be checked where it was made.
What it is not good for
known limits- It is not a scanner and it is not an alerting service. Finding a disclosure is not being told that you are exposed to it.
- A disclosure is what was published. Whether it applies to your version, your configuration or your deployment is a separate judgement.
Where it’s used
Code
The Code workspace reads this collection when a question is about a dependency rather than about your own code.
Read, filed and kept current.
This collection is one shelf of the askFinz index — material read from the source and filed as the kind of thing it is, rather than as undifferentiated web pages. The counts above are read from the running system.