google / google/osv.dev

OSV.dev downstream users have a clearly defined user journey to make corrections to OSV records served by OSV.dev with minimal overhead by all parties

Open
#2,191 4 comments 0 reactions 0 assignees View on GitHub
backlog
Dominant language
Go
Stars
2.9k
Forks
369
Avg merge
1d 17h
Merged PRs (30d)
149

Description

# Problem statement

OSV.dev users [often file issues in against OSV.dev](https://github.com/google/osv.dev/issues/) about records that OSV.dev is merely redistributing, and is not the originator of (what I call the "Don't shoot the messenger problem") and this is discussed in https://google.github.io/osv.dev/faq/#ive-found-something-wrong-with-the-data

The user experience of an OSV.dev user should be such that they are nudged as much as possible to the authoritative source (i.e. the home database) of a record so that they can make a correction or provide feedback where it can be most efficiently handled.

It's neither a good user experience nor a good use of limited resources for OSV.dev team members to act as an intermediary.

# Desired outcome

Make the UX around OSV.dev record correction as optimal as possible.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.