Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Show patched version of dependency in the dependency review summary #823

Open
virangdoshi opened this issue Aug 26, 2024 · 1 comment
Open
Labels
enhancement New feature or request

Comments

@virangdoshi
Copy link

virangdoshi commented Aug 26, 2024

In the PR summary, it would be nice to have a fix/patched version of the dependency, when a vulnerability is identified. The summary has vulnerability details, severity, etc. And additional column for "Patched Version" can be included as well. When a developer is looking at the summary, the patched version would help save time and avoid context switching in locating the patched version of the dependecy. Today, I have to click on the "vulnerability" link that points to the Github advisory database, which then contains the information on patched version of the dependency. The patched version column can be next to the severity column
screen

@virangdoshi virangdoshi added the enhancement New feature or request label Aug 26, 2024
@virangdoshi virangdoshi changed the title Show pacthed version of dependency in the dependency review summary Show patcthed version of dependency in the dependency review summary Aug 26, 2024
@virangdoshi virangdoshi changed the title Show patcthed version of dependency in the dependency review summary Show patched version of dependency in the dependency review summary Aug 26, 2024
@jonjanego
Copy link
Collaborator

Hi @virangdoshi , thank you for the suggestion.

In the meantime, I suggest you consider enabling Dependabot alerts for your repositories, which will alert you to vulnerable package versions, as well as suggest fixes to them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants