Skip to content

Feature Request: Clarify unspecified vulnerabilities #346

@AlexGustafsson

Description

@AlexGustafsson

User stories

  • As a user I want to understand the impact of vulnerabilities even if they're "unspecified"

Feature description

Cupdate showing unspecified vulnerability:

Image Image

Golang showing it as "unreviewed", that it's not verified and that there's no fix.

Image

GitHub showing it as low severity and with a known range.

Image

And then later explaining that there's indeed a known good release.

Image

For vulnerabilities with a known severity, Cupdate should report the severity. IIRC most osv.dev severities are "unspecified". Maybe we could look up references automatically?

Additionally, in cases where the final tag ends up being "unspecified", we should be able to tell the user in the UI that these results may or may not be an issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions