Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb/cmd/vulnreport: include a link to the release for GHSA reports #54901

Open
julieqiu opened this issue Sep 6, 2022 · 1 comment
Open
Assignees
Labels
NeedsFix The path to resolution is known, but the work has not been done. vulncheck or vulndb Issues for the x/vuln or x/vulndb repo

Comments

@julieqiu
Copy link
Member

julieqiu commented Sep 6, 2022

For example, for golang/vulndb#829, there was no commit link in the GHSA. It would be helpful to include this link in the issue for triaging:

https://github.com/crypto-org-chain/cronos/releases/tag/v0.8.0

@julieqiu julieqiu added the vulncheck or vulndb Issues for the x/vuln or x/vulndb repo label Sep 6, 2022
@gopherbot gopherbot added this to the Unreleased milestone Sep 6, 2022
@julieqiu julieqiu modified the milestones: Unreleased, vuln/2022 Sep 6, 2022
@mknyszek mknyszek added the NeedsFix The path to resolution is known, but the work has not been done. label Sep 6, 2022
@neild
Copy link
Contributor

neild commented Sep 23, 2022

Is there a simple, reliable way to map from a module name and version to a useful link?

We could perhaps say that if the module name begins with github.com, we link to https://${MODULE}/releases/tag/${VERSION}, but does that link reliably exist? And in the example here, does the page https://github.com/crypto-org-chain/cronos/releases/tag/v0.8.0 really contain that much useful information?

@julieqiu julieqiu modified the milestones: vuln/2022, vuln/unplanned Apr 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
NeedsFix The path to resolution is known, but the work has not been done. vulncheck or vulndb Issues for the x/vuln or x/vulndb repo
Projects
Status: No status
Development

No branches or pull requests

4 participants