Search for particular CVEs #177

Open
opened 2024-09-23 10:09:53 +00:00 by fricklerhandwerk · 2 comments
fricklerhandwerk commented 2024-09-23 10:09:53 +00:00 (Migrated from github.com)

As a member of the security team or a package maintainer, I want to be able to search for a particular CVE.

  • Show matching packages if a CVE is not triaged
  • Show linked security records on triaged CVEs

Depends on:

As a member of the security team or a package maintainer, I want to be able to search for a particular CVE. - [ ] Show matching packages if a CVE is not triaged - [ ] Show linked security records on triaged CVEs Depends on: - https://github.com/nix-security-wg/nix-security-tracker/issues/203 - https://github.com/nix-security-wg/nix-security-tracker/issues/200
erictapen commented 2024-09-24 10:42:37 +00:00 (Migrated from github.com)

Thinking about this more, I'm not even sure we need a suggestion for CVEs, as my current understanding of the triage workflow is, that the security team is only busy with working through all the new CVEs that are not marked yet.

So in the triage view, the primary concern would be to see a list of uncategorised CVEs that are assigned to a package one by one.

Thinking about this more, I'm not even sure we need a suggestion for CVEs, as my current understanding of the triage workflow is, that the security team is only busy with working through all the new CVEs that are not marked yet. So in the triage view, the primary concern would be to see a list of uncategorised CVEs that are assigned to a package one by one.
fricklerhandwerk commented 2024-09-24 11:08:48 +00:00 (Migrated from github.com)

Indeed, for package maintainers we'd need the inverse view. Each package maintainer "knows" their packages, and they may want automatic suggestions for CVEs. Both security team and package maintainers should be able to search back and forth though.

Indeed, for package maintainers we'd need the inverse view. Each package maintainer "knows" their packages, and they may want automatic suggestions for CVEs. Both security team and package maintainers should be able to search back and forth though.
Sign in to join this conversation.
No description provided.