Skip to content

chore: add explanations to TRIAGE.vex #3996

Closed
@terriko

Description

@terriko

In #3969, @mastersans has added a TRIAGE.vex file. Right now it marks our false positives but doesn't give a whole lot of detail as to why these things are false positives. In most cases right now, it's detecting a library with the sane name that's clearly written in another language and is not the same package, but that's not inherently obvious on a per-CVE basis.

I'd like to add some human readable explanation to the file. I forget off the top of my head if it's comments or remarks and what part of the data structure it should go in, but there should be a way to do this.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions