clomonitor icon indicating copy to clipboard operation
clomonitor copied to clipboard

Add "Security" check: project has published a CVE

Open caniszczyk opened this issue 3 years ago • 1 comments

We should check that a project has published a CVE

https://github.com/containerd/containerd/security/advisories

It shouldn't have a ton of weight but it's a good practice for projects to do so

caniszczyk avatar Feb 09 '22 22:02 caniszczyk

It looks like the Github GraphQL API doesn't allow yet to query security advisories by repository (Rest API doesn't expose this information). Will keep an eye on it though.

tegioz avatar Mar 01 '22 09:03 tegioz