Skip to content

Add CVEs in transitive dependencies section#8196

Draft
boblangley wants to merge 1 commit into
masterfrom
boblangley-patch-1
Draft

Add CVEs in transitive dependencies section#8196
boblangley wants to merge 1 commit into
masterfrom
boblangley-patch-1

Conversation

@boblangley
Copy link
Copy Markdown
Member

Added section on CVEs in transitive dependencies with scanning and issue tracking details.

@boblangley boblangley self-assigned this Apr 21, 2026
@Particular Particular deleted a comment from bording May 12, 2026
@abparticular abparticular self-assigned this May 19, 2026

- the affected product or repository scope
- the relevant advisory or CVE identifier
- affected versions or branches, where known
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: I don't think we publish anything related to branches

Suggested change
- affected versions or branches, where known
- affected versions


### 3. Repository and branch impact assessment

After initial recording, the affected repositories and branches are determined. For each affected repository/branch combination, the system creates a GitHub issue labeled as `Dependency CVE` that includes the advisory reference and branch context.
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: I don't think we should mention branches

Suggested change
After initial recording, the affected repositories and branches are determined. For each affected repository/branch combination, the system creates a GitHub issue labeled as `Dependency CVE` that includes the advisory reference and branch context.
After initial recording, the affected repositories and versions are determined. For each affected repository/version combination, the system creates a GitHub issue labeled as `Dependency CVE` that includes the advisory reference and necessary context.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants