prometheus-community / prometheus-community/postgres_exporter

Security and Release policies

Open
#768 0 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
3.6k
Forks
835
Avg merge
2d 4h
Merged PRs (30d)
10

Description

Automated security scanners detect many fixable CVEs for the latest postgres_exporter release.

  • Is there any publicly accessible place where those CVEs are listed and justified if they really have an impact on postgres_exporter in particular? See https://github.com/tianon/gosu/issues/104 as an example.
  • Would it make sense to have periodic releases that just update the dependencies, even if there are no new features added? Is there any ETA for the next stable release?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named in the issue. Start by reviewing the project's current release and dependency-management practices, then determine whether CVE impact assessments and a recurring dependency-update release policy should be documented. Done means the requested policy and next-release expectations are clearly recorded.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, postgresql
Domain
release, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.