-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add reference documentation about Vulnerability Management #109 #212
Conversation
Signed-off-by: tdruez <tdruez@nexb.com>
Signed-off-by: tdruez <tdruez@nexb.com>
Signed-off-by: tdruez <tdruez@nexb.com>
@tdruez Very impressive additions to the documentation, which is nicely comprehensive. I do not have any suggestions or corrections at this time. |
Signed-off-by: tdruez <tdruez@nexb.com>
Signed-off-by: tdruez <tdruez@nexb.com>
@DennisClark In addition to the "Vulnerability Management" chapter, I've added a new How To about "Product Vulnerability Analysis". Available at https://dejacode.readthedocs.io/en/109-vulnerability-documentation/howto-4-product-vulnerability-analysis.html for review. This should complete the #109 scope. |
@tdruez in Section 2 "Reviewing Vulnerabilities", the first sentence |
@tdruez Perhaps it would be nice to add the following "Note" at the end of the "3. Conducting Analysis" section: The analysis details that you provide for a product package vulnerability are included in the "vulnerabilities" sections of CycloneDX VEX and SBOM+VEX documents when you share them from your products. |
@tdruez The new "How To" is very nice and comprehensive; I have no additional suggestions beyond the two comments above. |
Signed-off-by: tdruez <tdruez@nexb.com>
#109
The current progress is published at https://dejacode.readthedocs.io/en/109-vulnerability-documentation/reference-vulnerability-management.html