Skip to content

feat(vulnerability): improve GitHub advisory PR body notes with summary, GHSA ID and references#42670

Open
Churro wants to merge 1 commit intorenovatebot:mainfrom
Churro:feat/github-vuln-summary
Open

feat(vulnerability): improve GitHub advisory PR body notes with summary, GHSA ID and references#42670
Churro wants to merge 1 commit intorenovatebot:mainfrom
Churro:feat/github-vuln-summary

Conversation

@Churro
Copy link
Copy Markdown
Collaborator

@Churro Churro commented Apr 15, 2026

Changes

  • Align the GitHub Dependabot vulnerability alert PR body notes with the format used by osvVulnerabilityAlerts
  • Add ghsa_id and summary fields to the GitHub SecurityAdvisory schema
  • Render advisory notes in a structured, collapsible format with attribution

Note: summary note ghsa_id are required per 2022-11-28 spec.

Context

Please select one of the following:

AI assistance disclosure

Did you use AI tools to create any part of this pull request?

Please select one option and, if yes, briefly describe how AI was used (e.g., code, tests, docs) and which tool(s) you used.

  • No — I did not use AI for this contribution.
  • Yes — minimal assistance (e.g., IDE autocomplete, small code completions, grammar fixes).
  • Yes — substantive assistance (AI-generated non‑trivial portions of code, tests, or documentation).
  • Yes — other (please describe):

Documentation (please check one with an [x])

  • I have updated the documentation, or
  • No documentation update is required

How I've tested my work (please select one)

I have verified these changes via:

  • Code inspection only, or
  • Newly added/modified unit tests, or
  • No unit tests, but ran on a real repository, or
  • Both unit tests + ran on a real repository

The public repository:

@github-actions github-actions bot requested a review from viceice April 15, 2026 20:51
@Churro Churro changed the title feat(vulnerability): improve GitHub advisory PR body notes with summary and GHSA ID feat(vulnerability): improve GitHub advisory PR body notes with summary, GHSA ID and references Apr 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant