Skip to content

Improve the "Add Package" process on the Package Vulnerabilities tab #14

@DennisClark

Description

@DennisClark

When you view the Vulnerabilities tab of a Package (see example screenshot) it presents the purl(s) of Fixed package(s) when available. If the Fixed package is not define in your dataspace, it activates a + icon to enable an "Add Package" process, which currently presents the Add Package form with only the available purl fields populated. An improved process would do the following (or something better and equivalent):

  • Use the purl to search the PurlDB (the one integrated with the current DejaCode Dataspace) for a match and, if found, fetch the data of the PurlDB entry to populate the Add Package form.
  • If no Download URL is available, attempt to infer it from the available data.
  • Initiate a scan when the new package is saved.

This improved process takes advantage of available integrations (VCIO, SCIO) and data resources when adding a new Package to DejaCode.

Example Package Vulnerabilities tab

Metadata

Metadata

Assignees

No one assigned

    Labels

    HighPriorityHigh Prioritydesign neededDesign details needed to complete the issueenhancementNew feature or requestintegrationIntegration with other applicationsvulnerabilitiesVulnerability Management

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions