aboutcode-org / aboutcode-org/vulnerablecode

History of Advisories

Open
#2,329 2 comments 0 reactions 0 assignees View on GitHub
insights
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

Right now, when an advisory is updated upstream, we create a new record in the db(mark it with `is_latest=True`) on the subsequent importer run but there is no way for a user to see ***`what`*** actually changed over time.

- At first we need a `Way Back Machine` mimic for advisories to see a advisory snapshot exactly how it was at that point in time
- We display the diffs between versions directly in the UI (if a severity score changes, a new reference is added, or a package is removed, users should be able to see exactly when and what happened at a glance)

**Suggested UX:**
- Add a "History" tab to the advisory detail page.
- Show a chronologically ordered list of versions of the advisory
- Allow users to click into a specific historical snapshot to view the advisory exactly as it was at that point in time, just like a way Back Machine
- Need a summary/diff of what changed for a quick overview

Excluding changes summary and epss score(can be tracked after merge of https://github.com/aboutcode-org/vulnerablecode/pull/2328 ; also since it changes everyday) might be good.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.