Navigation

    Inedo Community Forums

    Forums

    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    1. Home
    2. joacim.svensson_8194
    J
    • Profile
    • Following
    • Followers
    • Topics
    • Posts
    • Best
    • Groups

    joacim.svensson_8194

    @joacim.svensson_8194

    0
    Reputation
    4
    Posts
    1
    Profile views
    0
    Followers
    0
    Following
    Joined Last Online

    joacim.svensson_8194 Follow

    Best posts made by joacim.svensson_8194

    This user hasn't posted anything yet.

    Latest posts made by joacim.svensson_8194

    • RE: Is it possible to have feed-specific assessments of vulnerabilities?

      Hmm, that didnt work as expected. I added a second instance of OSS-index as a vulnerability source and used that second source on a specific feed. I let the scheduled job run last night and tried to download a package with a vulnerability in another feed but despite the same settings being applied to both feeds, and the same vulnerability source being used I managed to download the vulnerable package in one feed but not the other?

      posted in Support
      J
      joacim.svensson_8194
    • RE: Is it possible to have feed-specific assessments of vulnerabilities?

      @atripp Sorry, I completely missed your answer here.

      I'm wondering, even if I create a second source for vulnerabilities - isn't the vulnerability (and related block or no-block) global? Would dual sources mean that there would be duplicates of each vulnerability? The assessment doesn't seem related to the source, but rather to the vulnerability, or is that only how it appears in the UI?

      posted in Support
      J
      joacim.svensson_8194
    • Is it possible to have feed-specific assessments of vulnerabilities?

      We have a usecase where one of our internal application wants to utilise our global feeds ability to scan for vulnerabilities and automatic assessment but they want their own feed to do their own assessments that are application-specific.

      From what I've understood, scanning is feed-specific and blocking is feed-specific, but assessment is global? Am I missing something?

      posted in Support
      J
      joacim.svensson_8194
    • Edit vulnerability?

      Hi!
      Am I just a little bit dumb or illiterate or is there no way to edit a (manually added) vulnerability? Is the only option to deleted the old one and replace with a new one? In my case I want to edit the affected versions of a package and it seems very unintuitive having to create an almost identical new vulnerability just to accomplish that.

      posted in Support
      J
      joacim.svensson_8194