Skip to content

Automated/guided remediation #352

Open
@oliverchang

Description

@oliverchang

Tracking issue for building a guided remediation feature as part of OSV-Scanner.

Some ideas:

  • Suggesting direct dependency updates to remediate transitive vulns.
  • Ways to prioritize vulnerabilities based on things like dependency depth, severity, whether if it's dev-only etc.
  • Minimal re-locks to avoid known vulnerabilities in dependencies.
  • Automating upgrades with unit tests in a feedback loop.
  • Graph visualisations.

Current roadmap:

  • Q1 2024 for release of feature for npm.

Check out #352 (comment) for a walkthrough of what we've been building.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions