nix-security-tracker icon indicating copy to clipboard operation
nix-security-tracker copied to clipboard

Web service for managing information on vulnerabilities in software distributed through Nixpkgs

Results 113 nix-security-tracker issues
Sort by recently updated
recently updated
newest added

[Deployment through the module uses `daphne`](https://github.com/Nix-Security-WG/nix-security-tracker/blob/main/nix/web-security-tracker.nix#L217-L218), while the initial sync is [only run when doing `manage runserver`](https://github.com/Nix-Security-WG/nix-security-tracker/blob/main/src/website/shared/apps.py#L15). Make sure deployment always syncs on startup and sync can be ran manually...

bug
backend
deployment

Found values so far: - web-security-tracker - nix-security-tracker I'd vote for nix-security-tracker, as it's also the repository name.

contributor experience

`ingest_bulk_cve` uses WARNING to log information, it should be INFO.

data
contributor experience

Deploy the complete system to infrastructure managed by the NixOS infra team. - [ ] Production deployment (e.g. security.nixos.org) - [x] #227 Depends on: - https://github.com/Nix-Security-WG/nix-security-tracker/issues/228

contributor experience

_This issue is not in the scope of our paid work and sprints._ Currently, we have GitHub dependencies in two forms: - OAuth 2 connector - Foreign entities who are...

We should create a common module for SSH keys that can be called by the GH action playbook to render known hosts keys rather than duplicate them.

deployment

As a developer of the security tracker backend, I want to know which errors or inconsistencies there are with the data it is processing. This way we can fix the...

data
contributor experience
deployment

We have a bunch of performance sensitive code, it doesn't have to be suffering to capture performance data. Let's just have some OTEL integration. I can link this up to...

deployment

As a security team member, I want to have an overview of untriaged CVEs, displayed as a priority list. Each item in that list should only show the most relevant...

security team

Currently, ingesting the full CVE list and a copy of nixpkgs can take several hours, dramatically reducing iteration speed. To facilitate faster development, it would be useful to asynchronously generate...

nice to have
data
contributor experience
deployment