-
Notifications
You must be signed in to change notification settings - Fork 8
feat: add CSAF VEX document generation #170
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
zvigrinberg
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi @IlonaShishov
This looks good and does the work.
Though i have some comments. PTAL.
In addition, kindly modify openapi spec to reflect new output structure payload
https://github.com/RHEcosystemAppEng/vulnerability-analysis/blob/bb6f1b10685ac3801a22db7a1613a85da187cef3/src/vuln_analysis/configs/openapi/openapi.json
zvigrinberg
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great Job @IlonaShishov
LGTM Approved.
130d70e to
da03ec9
Compare
|
@IlonaShishov Please rebase on top of main. |
|
/test vulnerability-analysis-on-pr |
083827d to
c8e2592
Compare
zvigrinberg
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi @IlonaShishov
It looks good, i have only few minor comments.
Thanks!.
…SAF format support Signed-off-by: Ilona Shishov <[email protected]>
…ble CVEs only Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
…stants for reusability and readability Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
…ve intel score Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
Signed-off-by: Ilona Shishov <[email protected]>
zvigrinberg
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM Approved.
Generate machine-readable VEX documents in CSAF 2.0 format containing:
Includes pluggable VexGenerator architecture for future format support.
EIQ output has been remodeled to include a VEX field for the analysis as a whole. (output: {analysis: {}, vex: {}})