Uploaded image for project: 'Red Hat Advanced Cluster Security'
  1. Red Hat Advanced Cluster Security
  2. ROX-32251

Collect information about addressed RPM CVEs for Release

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None

      Currently, we don't have any steps in the release process to see which container/RPM CVEs are being addressed with the release and so we only mention CVEs from Vulnerability JIRA tickets. This is a gap.

      The process should be extended to do that. Ideally, we should get some automatic way (or at least a follow-up ticket for it).

      See discussion in https://redhat-internal.slack.com/archives/C05TS9N0S7L/p1765380787244339?thread_ts=1765356461.361239&cid=C05TS9N0S7L

              Unassigned Unassigned
              msugakov@redhat.com Misha Sugakov
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: