Uploaded image for project: 'Clair'
  1. Clair
  2. CLAIRDEV-53

Vulnerability inconsistency reporting pipeline

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • None
    • tooling
    • None
    • 8
    • False
    • False

      The Clair team should create a standardized form for reporting vulnerability inconsistencies. A standardized way to do this would ensure that reports are actionable and reproducible.

      Needs:

      • List of minimum required information, in a form:
      • Version
      • Configuration
      • Server Logs
      • Clair Client logs
      • Where/how to access the container
      • What/Why
      • Automation for validation and closing stale reports.

      Wants:

      • Vulnerability database export
      • Dropbox for uploading artifacts
      • Export needed information from Quay (on-prem only, presumably)

      Extra:

      • clairctl subcommand to submit reports

              Unassigned Unassigned
              hdonnay Henry Donnay
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: