google / google/osv-scanner

SARIF: add guidance on remediation

Open
#548 2 comments 0 reactions 0 assignees View on GitHub
backlog enhancement
Dominant language
Go
Stars
11k
Forks
792
Avg merge
1d 20h
Merged PRs (30d)
48

Description

We should add some remediation guidance to the OSV-Scanner SARIF output to let users know to remediate their vulnerabilities.

- Upgrade the vulnerable dependencies (in the future, point to #352).
- Create/add a config file to ignore the vulnerability.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.