spring-cloud / spring-cloud/spring-cloud-github-actions

When Given A Website PR, Add CVEs From That PR To Github Releases and Blog Post

Open
#8 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
0
Forks
0
Avg merge
2h 31m
Merged PRs (30d)
6

Description

When generating the GitHub releases and blog post for a release during a post release task it would be good if the workflow could extract CVE ids and links for the website PR and create links to the security reports in the Github release and website PR.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the post release task that generates the GitHub release and blog post, and trace how the website PR is provided. Define how CVE IDs and links from that PR should be identified, then verify that the generated release and blog post link to the corresponding security reports.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, github-actions
Domain
ci-cd, release
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.