Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create a new Manage action from DejaCode Product to get a Vulnerability Summary #155

Closed
DennisClark opened this issue Jul 30, 2024 · 2 comments
Assignees
Labels
design needed Design details needed to complete the issue enhancement New feature or request risk evaluate severity, exploitability, and context factors to determine a vulnerability risk score

Comments

@DennisClark
Copy link
Member

DennisClark commented Jul 30, 2024

Objective is to improve visibility of vulnerabilities associated with Product Inventory Items and to manage them. The basic concept is roughly equivalent to the License summary currently available on a Product Inventory.

Add a "Vulnerability summary" option to the Manage dropdown on Product Inventory.
Present a new form that lists the vulnerabilities associated with the Product Inventory items, including the following columns:
VulnerableCode URL (same field currently displayed on a Package with a vulnerability)
Summary (same field currently displayed on a Package with a vulnerability)
Policy (new field -- see related issue #97 )
Exploitability (new field -- see related issue #98 )
Items (equivalent to the Items column on the License summary)
{{other fields to be determined, such as VEX Status and a link to VEX details}}

Highlight items with an alert level policy (more details to be provided).

@DennisClark DennisClark added design needed Design details needed to complete the issue enhancement New feature or request labels Jul 30, 2024
@DennisClark DennisClark added the risk evaluate severity, exploitability, and context factors to determine a vulnerability risk score label Aug 9, 2024
@tdruez
Copy link
Contributor

tdruez commented Oct 24, 2024

@DennisClark Revisiting this issue, it seems that this was already implemented as the new "Vulnerabilities" tab in the Product details view. See #173

The missing pieces are Policy and Exploitability which will be handled in their own #97 and #98 issues.

Let me know if we can close this one.

@DennisClark
Copy link
Member Author

This was already implemented as the new "Vulnerabilities" tab in the Product details view. See #173

The missing pieces are Policy and Exploitability which will be handled in their own #97 and #98 issues.

Closing this one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
design needed Design details needed to complete the issue enhancement New feature or request risk evaluate severity, exploitability, and context factors to determine a vulnerability risk score
Projects
Status: Validated
Development

No branches or pull requests

2 participants