l3montree-dev / l3montree-dev/devguard
Dependency Risks: show CVE instead of GHSA
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 161
- Forks
- 43
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 37
Description
Is your feature request related to a problem? Please describe.
People are used to have CVE-XXX as primary identify for an "CVE" (haha..) - therefore it would be good to see the CVE instead of the GHSA ID within the Dependency Risks table.
Describe the solution you'd like
When available, use the official CVE-XXX instead of the GHSA inside the Dependency Risks table.
Example:
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the Dependency Risks table and the code that currently renders GHSA identifiers. Check how CVE data is represented for each risk, then verify that an official CVE is shown when available and the existing GHSA identifier remains the fallback.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 68/100