Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Vulnerability to package visibility #1430

PhilipCattanach started this conversation in Ideas
Discussion options

As I understand, and I'm happy to be corrected, is that in V2 packages can be ingested from both SBOMs and Advisories.
In version 1 all packages would originate from ingested SBOMs.
That is all fine.

However in V2, if there is a vulnerability affecting a package that does not belong to an SBOM, then it not possible to see via the UI which package the vulnerability is associated with.

This vulnerability to package data is exposed on the SBOM Detail screen Vulnerabilities tab.

image

I would suggest we need a third tab (Related packages) on the Vulnerabilities detail screen.

image

You must be logged in to vote

Replies: 1 comment

Comment options

It might help to further clarify the potential UX improvement.

In the package details page, trustify provides the list of the vulnerabilities affecting it

Screenshot 2025年03月14日 at 16 14 20

On the other side, in the vulnerability details page there's no way to know the affected package(s) if they are not inside an already ingested SBOM

Screenshot 2025年03月14日 at 16 14 29

In this context, having a Related package tab in the vulnerability details page would help the browsing from packages to vulnerabilities and viceversa.

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet

AltStyle によって変換されたページ (->オリジナル) /