aboutcode-org / dejacode

Automate open source license compliance and ensure software supply chain integrity
https://dejacode.readthedocs.io
GNU Affero General Public License v3.0
25 stars 8 forks source link

CRAVEX: Alerting/notification #106

Open pombredanne opened 6 months ago

pombredanne commented 6 months ago

Create a system to provide a alert/notification when new, not-yet-processed vulnerabilities are uncovered

DennisClark commented 5 months ago

Refer to issue https://github.com/nexB/dejacode/issues/94 for discussion of the vulnerability lookup process.

DennisClark commented 5 months ago

We can make use of the existing DejaCode Notifications feature to support this one.

Additionally (or alternatively) we could consider providing an ability to create a workflow request automatically to alert the appropriate users and to track the progress of the analysis and resolution.