l3montree-dev / l3montree-dev/devguard

Dependency Risks: show CVE instead of GHSA

Open Beginner friendly
#2,913 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

feature-request
Dominant language
Go
Stars
161
Forks
43
Avg merge
1d 8h
Merged PRs (30d)
37

Description

Is your feature request related to a problem? Please describe.
People are used to have CVE-XXX as primary identify for an "CVE" (haha..) - therefore it would be good to see the CVE instead of the GHSA ID within the Dependency Risks table.

Describe the solution you'd like
When available, use the official CVE-XXX instead of the GHSA inside the Dependency Risks table.

Example:

Image

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Dependency Risks table and the code that currently renders GHSA identifiers. Check how CVE data is represented for each risk, then verify that an official CVE is shown when available and the existing GHSA identifier remains the fallback.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.