Skip to content

Doc/security reports - #44

Merged
fredbi merged 2 commits into
masterfrom
doc/security-reports
Sep 25, 2026
Merged

fredbi merged 2 commits into
masterfrom
doc/security-reports

Conversation

@fredbi

@fredbi fredbi commented Sep 25, 2026

Copy link
Copy Markdown
Member

Change type

Please select: 🆕 New feature or enhancement|🔧 Bug fix'|📃 Documentation update

Short description

Fixes

Full description

Checklist

  • I have signed all my commits with my name and email (see DCO. This does not require a PGP-signed commit
  • I have rebased and squashed my work, so only one commit remains
  • I have added tests to cover my changes.
  • I have properly enriched go doc comments in code.
  • I have properly documented any breaking change.

fredbi and others added 2 commits September 26, 2026 00:10
Add a page listing, per repo of the go-openapi and go-swagger orgs, the
published security advisories and the code scanning / Dependabot alerts,
with the release that shipped each fix.

collect-security.sh writes hugo/data/security.json (gitignored), rendered
by the new `advisories` shortcode:

- Summary: per repo counts (published advisories, under analysis, fixed,
  fixed but not released, dismissed, open), per-org subtotals and a grand
  total. Pending items carry a ⚠️ linking to the maintainer pages.
- Detailed report: advisories under analysis counted per state (triage,
  draft); published advisories and fixed alerts newest release first;
  dismissed alerts counted by reason, open alerts by severity (never
  detailed). Alert ids link to NVD, pkg.go.dev/vuln, GitHub advisories or
  CodeQL query help: alert pages are visible to maintainers only.

Scorecard alerts are left out: they report best-practice compliance, not
releasable fixes.

Fix release of a code scanning alert: the first release whose tag contains
the commit of the analysis that saw the alert fixed (compare API). Dependabot
alerts record no commit: their release is inferred from the fix date (≈).
Fixes not yet released show their fix date.

A full run takes ~10 minutes (~2 API calls per fixed alert). Resolved fix
releases never change, so the output doubles as a cache (alertReleases,
-c / -f): a warm run takes ~1 minute. In CI, actions/cache carries
security.json from one daily run to the next.

The theme makes every row holding a <th> sticky; on narrow screens the
group and total rows piled up over the headers. Only the header sticks on
the security tables.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Frédéric BIDON <fredbi@yahoo.com>
State the current posture on CVE requests plainly: valid advisories are
fixed, released and published on GitHub's advisory database; CVE requests
are suspended until the influx of reports is triaged.

Update the intro to what the page shows (advisories and code scanning
alerts, reporters, severities, fix releases), and give the callout box its
title on the marker line so it renders in the box header.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Frédéric BIDON <fredbi@yahoo.com>
@fredbi
fredbi merged commit a596b1f into master Sep 25, 2026
6 of 7 checks passed
@fredbi
fredbi deleted the doc/security-reports branch September 25, 2026 22:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant