Sort suggested packages for a CVE by relevance #336

Open
opened 2024-11-11 11:22:56 +00:00 by fricklerhandwerk · 0 comments
fricklerhandwerk commented 2024-11-11 11:22:56 +00:00 (Migrated from github.com)

Even if we filter out dependants, some suggestions may have many packages jumbled together.

As a security team member, I want to view the most important ones first, and likely these are those where

  • the package name matches most closely
  • the CVE's version range is most similar
  • most keywords in the CVE description appear anywhere in derivation metadata or vice versa
Even if we filter out dependants, some suggestions may have many packages jumbled together. As a security team member, I want to view the most important ones first, and likely these are those where - the package name matches most closely - the CVE's version range is most similar - most keywords in the CVE description appear anywhere in derivation metadata or vice versa
Sign in to join this conversation.
No description provided.