Search for particular CVEs #177
Labels
No labels
automation
backend
bug
contributor experience
data
deployment
documentation
duplicate
good first issue
help wanted
nice to have
notifications
package maintainer
performance
skin
tech debt
user story
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: lix-community/nix-security-tracker#177
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
As a member of the security team or a package maintainer, I want to be able to search for a particular CVE.
Depends on:
Thinking about this more, I'm not even sure we need a suggestion for CVEs, as my current understanding of the triage workflow is, that the security team is only busy with working through all the new CVEs that are not marked yet.
So in the triage view, the primary concern would be to see a list of uncategorised CVEs that are assigned to a package one by one.
Indeed, for package maintainers we'd need the inverse view. Each package maintainer "knows" their packages, and they may want automatic suggestions for CVEs. Both security team and package maintainers should be able to search back and forth though.