prometheus-community / prometheus-community/postgres_exporter
Security and Release policies
Open
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 3.6k
- Forks
- 835
- Avg merge
- 2d 4h
- Merged PRs (30d)
- 10
Description
Automated security scanners detect many fixable CVEs for the latest postgres_exporter release.
- Is there any publicly accessible place where those CVEs are listed and justified if they really have an impact on
postgres_exporterin particular? See https://github.com/tianon/gosu/issues/104 as an example. - Would it make sense to have periodic releases that just update the dependencies, even if there are no new features added? Is there any ETA for the next stable release?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named in the issue. Start by reviewing the project's current release and dependency-management practices, then determine whether CVE impact assessments and a recurring dependency-update release policy should be documented. Done means the requested policy and next-release expectations are clearly recorded.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, postgresql
- Domain
- release, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100