Doc/security reports - #44
Merged
Merged
Conversation
Add a page listing, per repo of the go-openapi and go-swagger orgs, the published security advisories and the code scanning / Dependabot alerts, with the release that shipped each fix. collect-security.sh writes hugo/data/security.json (gitignored), rendered by the new `advisories` shortcode: - Summary: per repo counts (published advisories, under analysis, fixed, fixed but not released, dismissed, open), per-org subtotals and a grand total. Pending items carry a⚠️ linking to the maintainer pages. - Detailed report: advisories under analysis counted per state (triage, draft); published advisories and fixed alerts newest release first; dismissed alerts counted by reason, open alerts by severity (never detailed). Alert ids link to NVD, pkg.go.dev/vuln, GitHub advisories or CodeQL query help: alert pages are visible to maintainers only. Scorecard alerts are left out: they report best-practice compliance, not releasable fixes. Fix release of a code scanning alert: the first release whose tag contains the commit of the analysis that saw the alert fixed (compare API). Dependabot alerts record no commit: their release is inferred from the fix date (≈). Fixes not yet released show their fix date. A full run takes ~10 minutes (~2 API calls per fixed alert). Resolved fix releases never change, so the output doubles as a cache (alertReleases, -c / -f): a warm run takes ~1 minute. In CI, actions/cache carries security.json from one daily run to the next. The theme makes every row holding a <th> sticky; on narrow screens the group and total rows piled up over the headers. Only the header sticks on the security tables. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Frédéric BIDON <fredbi@yahoo.com>
State the current posture on CVE requests plainly: valid advisories are fixed, released and published on GitHub's advisory database; CVE requests are suspended until the influx of reports is triaged. Update the intro to what the page shows (advisories and code scanning alerts, reporters, severities, fix releases), and give the callout box its title on the marker line so it renders in the box header. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Frédéric BIDON <fredbi@yahoo.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change type
Please select: 🆕 New feature or enhancement|🔧 Bug fix'|📃 Documentation update
Short description
Fixes
Full description
Checklist