Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

glvd: implement minimum viable triage feature #127

Closed
fwilhe opened this issue Oct 14, 2024 · 9 comments
Closed

glvd: implement minimum viable triage feature #127

fwilhe opened this issue Oct 14, 2024 · 9 comments
Assignees
Milestone

Comments

@fwilhe
Copy link
Member

fwilhe commented Oct 14, 2024

for glvd, we need a way to set a state for cves that hides them from the default view

there are many old cves that are technically vulnerable, but in practice they are either fixed or not considered as an actual vulnerability.

we need some sort of triage feature. this requires changes to the database, and it requires some sort of writable api (so far our api is read-only on purpose to avoid having to deal with authn/authz)

@fwilhe fwilhe self-assigned this Oct 14, 2024
fwilhe added a commit to gardenlinux/glvd-api that referenced this issue Nov 14, 2024
fwilhe added a commit to gardenlinux/glvd-data-ingestion that referenced this issue Nov 15, 2024
changes the view sourcepackagecve so that it always returns the full list of cves so the client can filter for resolved.

This is maybe not great from a performance point of view, and it can be optimized later, but currently this seems to be what we need for the UI.

Part of gardenlinux/glvd#127
fwilhe added a commit to gardenlinux/glvd-api that referenced this issue Nov 15, 2024
Implements the following features:
- Allow viewing both resolved and unresolved issues in cve by distribution list
- Display of cve context in cve details

Part of gardenlinux/glvd#127
@fwilhe
Copy link
Member Author

fwilhe commented Nov 18, 2024

related: gardenlinux/glvd-contrib@d815419

@pnpavlov pnpavlov added this to the 2024-11 milestone Nov 20, 2024
@fwilhe
Copy link
Member Author

fwilhe commented Dec 16, 2024

Related work:

Add a wrapper script to run the triage more easily:

@fwilhe
Copy link
Member Author

fwilhe commented Dec 17, 2024

@fwilhe
Copy link
Member Author

fwilhe commented Jan 9, 2025

API to query cve details with context (triage information): gardenlinux/glvd-api#68

@fwilhe
Copy link
Member Author

fwilhe commented Jan 9, 2025

Setup minimal test data gardenlinux/glvd-api#69

@fwilhe
Copy link
Member Author

fwilhe commented Jan 10, 2025

Show triage info in a table, view more information like the distribution id gardenlinux/glvd-api#70

@fwilhe
Copy link
Member Author

fwilhe commented Jan 14, 2025

Better test setup for triage process gardenlinux/glvd-triage-cli#1

@fwilhe
Copy link
Member Author

fwilhe commented Jan 14, 2025

Show last modified and ingested date

gardenlinux/glvd-api#73

gardenlinux/glvd-data-ingestion#15

@fwilhe
Copy link
Member Author

fwilhe commented Jan 15, 2025

Closing as completed. We have a minimum triage feature, further development will be reflected in separate issues.

@fwilhe fwilhe closed this as completed Jan 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants