-
Notifications
You must be signed in to change notification settings - Fork 6
Feature Request: Clarify unspecified vulnerabilities #346
Copy link
Copy link
Open
Labels
enhancementNew feature or requestNew feature or request
Description
User stories
- As a user I want to understand the impact of vulnerabilities even if they're "unspecified"
Feature description
Cupdate showing unspecified vulnerability:
Golang showing it as "unreviewed", that it's not verified and that there's no fix.
GitHub showing it as low severity and with a known range.
And then later explaining that there's indeed a known good release.
For vulnerabilities with a known severity, Cupdate should report the severity. IIRC most osv.dev severities are "unspecified". Maybe we could look up references automatically?
Additionally, in cases where the final tag ends up being "unspecified", we should be able to tell the user in the UI that these results may or may not be an issue.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request