fleetdm / fleet

Open-source platform for IT, security, and infrastructure teams. (Linux, macOS, Chrome, Windows, cloud, data center)
https://fleetdm.com
Other
2.92k stars 409 forks source link

Get accurate vulns for Google Chrome browser plugins (extensions) #14827

Open zayhanlon opened 10 months ago

zayhanlon commented 10 months ago

This issue's remaining effort can be completed in ≤1 sprint. It will be valuable even if nothing else ships.

It is planned and ready to implement. It is on the proper kanban board.

Goal

User story
As a vulnerability management engineer,
I want Fleet to use a source outside of the National Vulnerability Database (NVD) to detect vulnerabilities in Google Chrome browser plugins (extensions)
so that I can get an accurate report of vulnerable browser plugins installed on my hosts.

Changes

Product

Engineering

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

Context

QA

Risk assessment

Manual testing steps

  1. Step 1
  2. Step 2
  3. Step 3

Testing notes

Confirmation

  1. [ ] Engineer (@____): Added comment to user story confirming succesful completion of QA.
  2. [ ] QA (@____): Added comment to user story confirming succesful completion of QA.
noahtalerman commented 10 months ago

Feature fest: Why just investigate? We should make this about getting accurate vuln data for browser extensions. Take this.

noahtalerman commented 10 months ago

@zayhanlon heads up, we pulled this into the upcoming design sprint.

rachaelshaw commented 9 months ago

@zayhanlon we didn't get to this in the current design sprint, bringing this back to Feature Fest.

marko-lisica commented 9 months ago

@zayhanlon We didn't get to this one in the current design sprint. Adding it to feature fest.

noahtalerman commented 8 months ago

Heads up @zayhanlon this request was discussed during feature fest last week and didn't make it into the current design sprint.