Skip to content

Explain CVE remediation for vendored dependencies#3228

Merged
s-stumbo merged 2 commits intomainfrom
cve-clarify
Apr 13, 2026
Merged

Explain CVE remediation for vendored dependencies#3228
s-stumbo merged 2 commits intomainfrom
cve-clarify

Conversation

@s-stumbo
Copy link
Copy Markdown
Collaborator

[ ] Check if this is a typo or other quick fix and ignore the rest :)

Type of change

Update to library CVE remediations page

What should this PR do?

Clarify how CVE remediations work for Python packages when a CVE exists in a dependency of vendored code

Why are we making this change?

To prevent confusion if customers see +cgr.N versions of a package but no advisory in the VEX feed. Thread here.

What are the acceptance criteria?

Content should clearly explain how this works

Signed-off-by: s-stumbo <sally.stumbo@chainguard.dev>
@s-stumbo s-stumbo requested a review from a team as a code owner April 10, 2026 16:42
@netlify
Copy link
Copy Markdown

netlify Bot commented Apr 10, 2026

Deploy Preview for ornate-narwhal-088216 ready!

Name Link
🔨 Latest commit 018ffe7
🔍 Latest deploy log https://app.netlify.com/projects/ornate-narwhal-088216/deploys/69d92b83ce175f0008e73e61
😎 Deploy Preview https://deploy-preview-3228--ornate-narwhal-088216.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Comment thread content/chainguard/libraries/cve-remediation.md Outdated
Comment thread content/chainguard/libraries/cve-remediation.md Outdated
Copy link
Copy Markdown
Member

@wiedenmeier wiedenmeier left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, just a few little nits

Signed-off-by: s-stumbo <sally.stumbo@chainguard.dev>
Copy link
Copy Markdown
Collaborator

@matthewhelmke matthewhelmke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's very clear, thank you!
LGTM

@s-stumbo s-stumbo merged commit 46eb3a0 into main Apr 13, 2026
13 checks passed
@s-stumbo s-stumbo deleted the cve-clarify branch April 13, 2026 17:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants