Vulnerability to package visibility #1430
PhilipCattanach
started this conversation in
Ideas
Replies: 1 comment
-
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment


Uh oh!
There was an error while loading. Please reload this page.
-
As I understand, and I'm happy to be corrected, is that in V2 packages can be ingested from both SBOMs and Advisories.
In version 1 all packages would originate from ingested SBOMs.
That is all fine.
However in V2, if there is a vulnerability affecting a package that does not belong to an SBOM, then it not possible to see via the UI which package the vulnerability is associated with.
This vulnerability to package data is exposed on the SBOM Detail screen Vulnerabilities tab.
I would suggest we need a third tab (Related packages) on the Vulnerabilities detail screen.
Beta Was this translation helpful? Give feedback.
All reactions