Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove the must be closed requirement in CVE feed #106

Merged
merged 1 commit into from
Nov 16, 2023

Conversation

enj
Copy link
Member

@enj enj commented Nov 16, 2023

The official-cve-feed label is sufficient in filtering down to valid issues.

@kubernetes/security-response-committee @kubernetes/sig-security-pr-reviews @PushkarJ

For example, currently kubernetes/kubernetes#121879 is open and published to mitre but not included in the CVE feed which seems like the wrong approach. We do not add the official-cve-feed label until we fill out the issue details, so I do not think there is any need to wait until the issue is closed before including it in the feed.

The `official-cve-feed` label is sufficient in filtering down to valid issues.
@k8s-ci-robot k8s-ci-robot added sig/security Categorizes an issue or PR as relevant to SIG Security. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Nov 16, 2023
@k8s-ci-robot k8s-ci-robot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Nov 16, 2023
@cji
Copy link
Member

cji commented Nov 16, 2023

/lgtm

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Nov 16, 2023
@cji cji removed their assignment Nov 16, 2023
@PushkarJ
Copy link
Member

This has been a feature request that was made earlier here: #97

We discussed this in the SIG Security call too today, and there were no concerns raised.

Only note I will make is we need to add a status field as a next step in the CVE feed

/approve

@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: enj, PushkarJ

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 16, 2023
@k8s-ci-robot k8s-ci-robot merged commit 8cf0dd5 into kubernetes:main Nov 16, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. sig/security Categorizes an issue or PR as relevant to SIG Security. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants