google / osv.dev

Open source vulnerability DB and triage service.

Home Page:https://osv.dev

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Add `osv-scanner fix` and GitHub actions to osv.dev home page.

oliverchang opened this issue · comments

We have examples of OSV-Scanner usages on the home page. We should expand them with guided remediation and GitHub actions.

@oliverchang I'm not sure of the exact acceptance criteria in this task. Do you mean we need to add some introduction text about the osv-scanner in the Home page? or just adding links of announcing-guided-remediation-in-osv-scanner blog post or guided remediation docs and Github Actions docs is enough?

Also, currently the More details button links to the osv-scanner github page. What do you think of updating it to the osv-scanner documentation instead.

@oliverchang I'm not sure of the exact acceptance criteria in this task. Do you mean we need to add some introduction text about the osv-scanner in the Home page? or just adding links of announcing-guided-remediation-in-osv-scanner blog post or guided remediation docs and Github Actions docs is enough?

I mean adding some inline examples of invocations to osv-scanner fix, similar to how we have examples for "Scan SBOM or Lockfiles" and perhaps a screenshot of https://github.com/google/osv-scanner-action in actions.

Also, currently the More details button links to the osv-scanner github page. What do you think of updating it to the osv-scanner documentation instead.

Yes, that's a better link.

Thanks for the clarification. I'm planning to work on this issue.