Skip to content

Automatic removal of older exploitability statements #6

@dsseng

Description

@dsseng

Advisories become stale overtime, as vulnerability database improve data quality and older software components with vulnerabilities we patch or disable are being replaced with unaffected versions.

For now there are comments indicating when the CVE no longer applies, and after no supported branch of Talos supports this version the statement should be removed. Find a more automated way, so that CLI could e.g. automatically prune records when given an SBOM for the oldest supported branch

Originally posted by @frezbo in #5 (comment)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    To Do

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions