Skip to content

New CVE YAML field for affected methods? #492

Open
@ghbren

Description

@ghbren

Would it be possible to enforce a yaml field for the methods affected by each vulnerability?

Almost all CVEs appear to only affect a very small subset of methods, and there is no need to upgrade the bad gems if the affected method are not used. This new field will help us to automatically eliminate the need to upgrade a large set of gems.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions