Skip to content

Private repositories: findings as security-finding issues #540

Description

@JacobStephens2

Parent

#427

What to build

GitHub keeps repository security advisories for public repositories: its advisories API answers 404 on a private one. On a private repository, a Security run records each Security finding as an issue labelled security-finding and needs-triage. The issue's body is the one a draft advisory would have, and it is matched by fingerprint, so that a repeat audit doesn't duplicate it.

Both labels are created with a description when the repository lacks them.

Acceptance criteria

  • On a repository whose advisories API answers 404, each finding becomes an issue labelled security-finding and needs-triage, with the advisory's body.
  • A second audit with the same finding creates no second issue.
  • Missing labels are created, each with a description, and existing ones are kept as they are.
  • A public repository still gets draft advisories and no issues.

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentFully specified, ready for an AFK agent

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions