aboutcode-org / aboutcode-org/dejacode

Design VEX changes for Advisories

Đang mở
#452 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
design needed
Ngôn ngữ chính
Python
Star
50
Fork
27
Merge trung bình
4 giờ 51 phút
Pull request đã merge (30 ngày)
11

Mô tả

The planned Vulnerablecode change for the migration to Advisories instead of Vulnerabilities will have a significant impact on the current VEX functionality in DejaCode which is currently "keyed" by Vulnerability.

Looking at the example of: https://public.dejacode.com/products/Evaluation/DejaCode/5.1/#vulnerabilities in DjC Evaluation, it seems that we will be missing the VCID to group related advisories and this will make the display much more complex.
- Have we ruled out having something like VCID to group advisories - perhaps the aliases from the advisory record? It is difficult to suggest how to display without some way to group obviously related advisories.
- It looks like the change will make the VEX reporting more complex if we cannot logically group them so that a user can apply one VEX statement to many advisories.
- We may also need to consider a DejaCode configuration option to filter the Advisories that are imported into DejaCode based on the origin (importer). For example a user might want to ignore RedHat advisories if they do not use RedHat products. Red Hat is an interesting example because there are multiple datasets to exclude - e.g. Red Hat, Fedora and ? If some Advisories are excluded we would want some way to alert the user about the intentional exclusion and the availability of additional data.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.