Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

As a user, I can spot packages impacted by a security vulnerability #11

Open
2 tasks
GuillaumeDesforges opened this issue Oct 14, 2022 · 1 comment
Open
2 tasks

Comments

@GuillaumeDesforges
Copy link
Contributor

Tasks

  • Enrich graph with security vulnerability database
  • Display security vulnerability in the UI
@aspiwack
Copy link
Member

You had a little more than this to say about this user story. I think we can make this issue a little bit more meaty.

  • “As a user” is very vague, where is this user coming from, what are they doing that requires attention to security vulnerability?
  • Based on that, what does “spotting packages impacted by a security vulnerability” looks like? Are they auditing the entirety of Nix? A package that they are installing? A package in their transitive dependencies? What do they need to know?
  • What would a solution look like which answers that need? Would it be an API? Or would it be a web UI element? In either case, what would it provide? A list of packages? A graph of packages with a given property? Something else? If it's a visual element, would their be some visual aid, or would the element be self-sufficient?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants