fix: improve output of cve-scan github action for cve #2475
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Signed-off-by: ayush_gitk ayushsharmaa101@gmail.com
This pr fixes #2424 .
Current behaviour:
Current output of the CVE-scan github action tells us that we have a unexplored potential CVE in a component but it's not telling us what component it's in ,as described in the issue.
Desired behaviour:
We want the output to tell name of component having vulnerability. (in the assert message)
Steps i took to solve:
First i introduced a fake vulnerability
kubernetes == 1.0.1
in requirements.txt fileThen i made the desired code changes in test_requirements.py ,present in this pr
This is the screenshot of the cve-scan github action i got which has the message "Component kubernetes has a unexplored CVE" corresponding to the fake vulnerability i injected.
data:image/s3,"s3://crabby-images/f538c/f538c28e95833fef7bfc0f6617854f43ae3d94c8" alt="Screenshot from 2022-12-29 02-47-28"