Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Show patched version of dependency in the dependency review summary #823

Open
virangdoshi opened this issue Aug 26, 2024 · 2 comments
Open
Labels
enhancement New feature or request Stale

Comments

@virangdoshi
Copy link

virangdoshi commented Aug 26, 2024

In the PR summary, it would be nice to have a fix/patched version of the dependency, when a vulnerability is identified. The summary has vulnerability details, severity, etc. And additional column for "Patched Version" can be included as well. When a developer is looking at the summary, the patched version would help save time and avoid context switching in locating the patched version of the dependecy. Today, I have to click on the "vulnerability" link that points to the Github advisory database, which then contains the information on patched version of the dependency. The patched version column can be next to the severity column
screen

@virangdoshi virangdoshi added the enhancement New feature or request label Aug 26, 2024
@virangdoshi virangdoshi changed the title Show pacthed version of dependency in the dependency review summary Show patcthed version of dependency in the dependency review summary Aug 26, 2024
@virangdoshi virangdoshi changed the title Show patcthed version of dependency in the dependency review summary Show patched version of dependency in the dependency review summary Aug 26, 2024
@jonjanego
Copy link
Collaborator

Hi @virangdoshi , thank you for the suggestion.

In the meantime, I suggest you consider enabling Dependabot alerts for your repositories, which will alert you to vulnerable package versions, as well as suggest fixes to them.

Copy link

👋 This issue has been marked as stale because it has been open with no activity for 180 days. You can: comment on the issue or remove the stale label to hold stalebot off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing, this issue will be closed eventually by the stalebot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions bot added the Stale label Feb 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request Stale
Projects
None yet
Development

No branches or pull requests

2 participants