Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Given an SBOM get the Vulnerabilities that affect that SBOM #285

Open
carlosthe19916 opened this issue May 14, 2024 · 2 comments
Open

Given an SBOM get the Vulnerabilities that affect that SBOM #285

carlosthe19916 opened this issue May 14, 2024 · 2 comments
Assignees
Labels
frontend Frontend related code changes

Comments

@carlosthe19916
Copy link
Member

For each SBOM there should be a way of getting the vulnerabilities/cves counts per severity. That information will be used in the image below. This is one of the 3 use cases described in the original design of Trustification.

Screenshot from 2024-05-14 12-57-20

@carlosthe19916 carlosthe19916 added the frontend Frontend related code changes label May 14, 2024
@carlosthe19916
Copy link
Member Author

Update as of 1st July:
We need to know the whole list of Vulnerabilities that affect a given SBOM. Depending of the size of this list we can delegate the creation of the summary to the client or to the server side.

@carlosthe19916 carlosthe19916 changed the title Given an SBOM, get a summary of vulnerabilities that affect the SBOM Given an SBOM get the Vulnerabilities that affect that SBOM Jul 1, 2024
@carlosthe19916 carlosthe19916 pinned this issue Jul 1, 2024
@carlosthe19916
Copy link
Member Author

@bobmcwhirter I can see that this other Issue has been closed #282
Vulnerabilty -> SBOM

And this current issue is about the other way around SBOM -> Vulnerability

Just droping a message here so we don't forget about this issue :)

@bobmcwhirter bobmcwhirter self-assigned this Jul 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
frontend Frontend related code changes
Projects
Status: No status
Development

No branches or pull requests

2 participants