python / python/psrt-ghsa-bot

Allow collaborators to "publish" a CVE ID

Open
#5 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
6
Forks
2
Avg merge
9h 7m
Merged PRs (30d)
2

Description

Command to the bot which allows any collaborator to mark a report as "complete" through publication of an advisory. Need to figure out how affected versions will be documented.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the bot's command handling and its GitHub Security Advisory workflow. Define how a collaborator command marks a report complete through publication and how affected versions are documented. Done means the command and version representation are specified and covered by appropriate tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, python
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.