Skip to content

Conversation

@tdruez
Copy link
Contributor

@tdruez tdruez commented Aug 29, 2024

No description provided.

@tdruez
Copy link
Contributor Author

tdruez commented Aug 30, 2024

@DennisClark This is ready for review.
A new "Vulnerabilities" tab is available in the Product details view, listing all vulnerabilities of a Product. With the ability to filter and sort by score.
Note that the tab is displayed but disabled if no vulnerabilities is found for the Product.

@DennisClark
Copy link
Member

@tdruez The new "Vulnerabilities" tab is very impressive, and performance is excellent; however, I noticed a discrepancy that is a bit confusing. In Staging Starship, I opened product Astrolabe 2.5.7 and the Vulnerabilities tab presents 25 rows, but when I go to the Inventory tab and use the Filter "Affected by vulnerabilities", I only see 11 rows.

Wait, I think I just figured it out. One of the packages pkg:pypi/[email protected] has 13 vulnerabilities, and some others have more than one as well. The Inventory tab is a listing of packages (and components) and the Vulnerabilities tab is a listing of the vulnerabilities, and one can easily see that a number of packages are repeated in the right column. Great.

So far so good then ! No problems found.

@DennisClark
Copy link
Member

@tdruez , the new Vulnerabilities tab works quite well to provide information, and in that respect it is working just fine. I think we still need the filter on the Inventory tab, because that is where the user can access the Product-Package relationship and update the review status and add notes, etc.

I think this one is ready to deploy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants