nix-security-tracker icon indicating copy to clipboard operation
nix-security-tracker copied to clipboard

View a list of pre-computed match suggestions

Open fricklerhandwerk opened this issue 5 months ago • 1 comments

As a security team member, I want to have an overview of untriaged CVEs, displayed as a priority list.

Each item in that list should only show the most relevant information:

  • CVE ID
  • CVE logline
  • Number of derivations affected
  • Number of channels affected

The list should be sorted by some reasonable combination of

  • CVE age
  • CVE severity
  • Relevance for Nixpkgs (e.g. number of supposedly affected derivations)
  • Confidence in the matching of CVE and Nixpkgs metadata

Depends on:

  • #221

fricklerhandwerk avatar Sep 26 '24 18:09 fricklerhandwerk