Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

x/vulndb/cmd/vulnreport: include a link to the release for GHSA reports #54901

Open
julieqiu opened this issue Sep 6, 2022 · 1 comment
Open
Assignees
Labels
NeedsFix The path to resolution is known, but the work has not been done. vulncheck or vulndb Issues for the x/vuln or x/vulndb repo

Comments

@julieqiu
Copy link
Member

julieqiu commented Sep 6, 2022

For example, for golang/vulndb#829, there was no commit link in the GHSA. It would be helpful to include this link in the issue for triaging:

https://github.com/crypto-org-chain/cronos/releases/tag/v0.8.0

@julieqiu julieqiu added the vulncheck or vulndb Issues for the x/vuln or x/vulndb repo label Sep 6, 2022
@gopherbot gopherbot added this to the Unreleased milestone Sep 6, 2022
@julieqiu julieqiu modified the milestones: Unreleased, vuln/2022 Sep 6, 2022
@mknyszek mknyszek added the NeedsFix The path to resolution is known, but the work has not been done. label Sep 6, 2022
@neild
Copy link
Contributor

neild commented Sep 23, 2022

Is there a simple, reliable way to map from a module name and version to a useful link?

We could perhaps say that if the module name begins with github.com, we link to https://${MODULE}/releases/tag/${VERSION}, but does that link reliably exist? And in the example here, does the page https://github.com/crypto-org-chain/cronos/releases/tag/v0.8.0 really contain that much useful information?

@julieqiu julieqiu modified the milestones: vuln/2022, vuln/unplanned Apr 7, 2023
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
NeedsFix The path to resolution is known, but the work has not been done. vulncheck or vulndb Issues for the x/vuln or x/vulndb repo
Projects
Status: No status
Development

No branches or pull requests

4 participants