Skip to content

Commit 8e82f28

Browse files
authored
add electron as a source (xs sized PR) (#1921)
* add electron as a source * add electron as source
1 parent 62bd29f commit 8e82f28

File tree

2 files changed

+9
-4
lines changed

2 files changed

+9
-4
lines changed

docs/semgrep-supply-chain/sbom.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,6 @@ In addition to the [<i class="fas fa-external-link fa-xs"></i> minimum elements
5656
| Description | A short description of the vulnerability. |
5757
| Detail | A longer description of the vulnerability, including the affected versions. |
5858
| Ratings | Semgrep Supply Chain's severity rating of this vulnerability. |
59-
| References | Links to the specific CVE. References can come from NIST and GitHub Security Advisory. |
59+
| References | Links to the specific CVE. References can come from NIST, Electron release notes, and GitHub Security Advisory. |
6060
| Source | The primary source of this vulnerability's advisory. |
6161
| Tools | Details about Semgrep, the tool used to generate the SBOM. |
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,11 @@
11
### Semgrep Supply Chain rule update frequency
22

3-
Semgrep ingests CVE information and security advisories from sources such as [Reviewed GitHub Security Advisories](https://github.com/advisories?query=type%3Areviewed) to ensure effective rule coverage. Semgrep processes new information at least once per day to:
3+
Semgrep ingests CVE information and security advisories from the following sources:
44

5-
* Generate rules for new security advisories;
6-
* Update rules based on changes to existing security advisories.
5+
- [<i class="fas fa-external-link fa-xs"></i> Reviewed GitHub Security Advisories](https://github.com/advisories?query=type%3Areviewed)
6+
- [<i class="fas fa-external-link fa-xs"></i> Electron release notes](https://releases.electronjs.org/releases/stable)
7+
8+
Semgrep processes new information at least once per day to:
9+
10+
* Generate rules for new security advisories
11+
* Update rules based on changes to existing security advisories

0 commit comments

Comments
 (0)