Skip to content

Screening of CVEs #33

Description

@sh4sm

We need to introduce a screening component. It will get the data we now have about a CVE, the PURLs of packages this CVE is related to and the Debian Security Tracker entry for the CVE.

With this information the screening component has to decide if a CVE is relevant for GL in general. For example currently CVE for the X window manger are not relevant for GL, but relevant for Debian. Moreover, we should filter out all CVEs not related to a Linux operating system (e.g. Microsoft products, we do not ship).

We can use the Debian Security Tracker "not for us"-data to create a baseline for this decision, which we can then extend to filter specifically for GL. Store this baseline and overwrites also transparently via the audit component inside the repository.

The screening service should store its decisions for a CVE inside the assessment record of the CVE.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions