Skip to content

Improve dependency scanning triage, license, and manifest coverage#1167

Open
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/dependency-scanning-vex-coverage
Open

Improve dependency scanning triage, license, and manifest coverage#1167
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/dependency-scanning-vex-coverage

Conversation

@KooZuKi
Copy link
Copy Markdown

@KooZuKi KooZuKi commented Jun 5, 2026

Summary

  • Add reachability/VEX context to vulnerability triage so non-exploitable or not-affected findings can be tracked appropriately.
  • Replace substring-style license guidance with SPDX expression/exception parsing and distributed-vs-dev scoping.
  • Expand manifest coverage for pyproject.toml, NuGet, Composer, Ruby, Dart, and Elixir ecosystems.
  • Add lockfile drift, git/URL/tarball dependency, resolved install-script, EPSS percentile, and KEV-absence guidance.

Validation

  • git diff --check
  • Local frontmatter check using the repository workflow required fields
  • Local prompt-injection scan using the repository workflow patterns

Closes #1143

Bounty

Improver contribution. Preferred payment method can be provided privately after acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] dependency-scanning: SPDX-expression license FPs, no reachability/VEX, missing manifests & git/URL deps

1 participant