Sign in
◑
Theme
apache
/
security-vulnogram
/
HEAD
5b96a28
fix: keep bearer-token authentication to the request (#269)
by Jarek Potiuk
· 14 hours ago
main
44e8c1b
feat(cve5): show the repository when set and require a GitBox URL (#271)
by Piotr P. Karwasz
· 15 hours ago
6a86e45
fix: name each product once in the published title (#270)
by Piotr P. Karwasz
· 19 hours ago
0eaee4c
Drop advisory URL from subject (#267)
by Sebb
· 32 hours ago
cfb2b48
fix: treat an unset NODE_ENV as development (#268)
by Jarek Potiuk
· 34 hours ago
9ffa163
Merge pull request #264 from potiuk/token-authorize
by Arnout Engelen
· 36 hours ago
86e258a
feat(allocate): return the allocated CVE ID as JSON to token callers
by Jarek Potiuk
· 2 days ago
73ec7ed
feat(token): allow requesting allocate tokens through the browser
by Jarek Potiuk
· 2 days ago
e32434f
Merge branch 'main' into token-authorize
by Arnout Engelen
· 8 days ago
8b0f147
fix: apply PMC record ownership consistently across record routes (#265)
by Jarek Potiuk
· 10 days ago
61df422
docs(token): add a design doc for browser-approved tokens
by Jarek Potiuk
· 11 days ago
c293f25
feat(token): let tools request a PMC-scoped token through the browser
by Jarek Potiuk
· 11 days ago
52fc959
feat: show CVSS ratings in notification emails (#225)
by Shreemaan Abhishek
· 2 weeks ago
f29199c
fix(cve5): do not require the Package URL (#258)
by Piotr P. Karwasz
· 3 weeks ago
a9dc776
feat(cve5): derive legacy package identifiers from the Package URL (#253)
by Piotr P. Karwasz
· 3 weeks ago
ae349ac
fix: default metrics for new advisories (#256)
by Arnout Engelen
· 3 weeks ago
3212b85
auth: make more oauth parameters configurable (#251)
by Arnout Engelen
· 3 weeks ago
ec4b71d
Merge pull request #252 from raboof/api-allocate
by Arnout Engelen
· 4 weeks ago
22f36c7
feat(allocate): allow allocating CVEs using a Bearer token
by Arnout Engelen
· 4 weeks ago
4ea4835
require at least one severity rating (#250)
by Arnout Engelen
· 4 weeks ago
dacfb61
deployment: don't restart update-deps jobs
by Arnout Engelen
· 4 weeks ago
4290164
fix(cvepublish): show error when CVE publication fails (#247)
by Arnout Engelen
· 5 weeks ago
91a5860
feat: don't redirect after publishing (#238)
by Arnout Engelen
· 5 weeks ago
1b5a7fb
Merge pull request #244 from apache/fix/asf-metric-missing-type
by Arnout Engelen
· 5 weeks ago
7c50619
fix: minimize change
by Piotr P. Karwasz
· 5 weeks ago
fix/asf-metric-missing-type
04df207
fix: ASF severity metric added to existing record lacks 'other.type'
by Piotr P. Karwasz
· 5 weeks ago
b606271
feat: accept pmc, title and message/list id (#241)
by Arnout Engelen
· 5 weeks ago
99eab23
feat: hide sidebar (#239)
by Arnout Engelen
· 5 weeks ago
bab161a
chore: hide 'Scoring scenarios' from metrics (#237)
by Arnout Engelen
· 5 weeks ago
4cf0318
fix: comment footer link (#235)
by Arnout Engelen
· 5 weeks ago
f097fa2
fix(api): allow POST via API (#228)
by Arnout Engelen
· 5 weeks ago
de8449b
Bump actions/setup-node from 6 to 7 (#230)
by dependabot[bot]
· 5 weeks ago
b1f8793
Merge pull request #231 from apache/dependabot/github_actions/actions/checkout-7
by Arnout Engelen
· 6 weeks ago
507f539
Bump actions/checkout from 6 to 7
by dependabot[bot]
· 6 weeks ago
eb3de5e
Merge pull request #236 from raboof/fix-codeql
by Arnout Engelen
· 6 weeks ago
b73f1b4
chore(ci): fix codeql
by Arnout Engelen
· 6 weeks ago
e2615db
Merge pull request #227 from raboof/fix-sending-notification-emails
by Arnout Engelen
· 6 weeks ago
eeaf8fa
Merge pull request #229 from raboof/remove-cveportal-from-sidebar
by Arnout Engelen
· 6 weeks ago
d13b7cc
Merge pull request #205 from apache/pmcs-with-security-emails
by Arnout Engelen
· 6 weeks ago
9c9b6c3
add more missing security lists
by Arnout Engelen
· 6 weeks ago
pmcs-with-security-emails
280cb9a
fix: sending notification emails
by Arnout Engelen
· 6 weeks ago
790d6c9
Merge pull request #220 from raboof/fix
by Arnout Engelen
· 6 weeks ago
687a750
fix: follow-up on publicjson fixes
by Arnout Engelen
· 6 weeks ago
8c89f36
Merge pull request #219 from raboof/use-promise-mongo-api
by Arnout Engelen
· 6 weeks ago
7a72dde
fix(api): fetch public CVEs
by Arnout Engelen
· 6 weeks ago
df41369
Merge pull request #218 from apache/main-next
by Arnout Engelen
· 6 weeks ago
fad0f35
fix: use correct header name for bearer tokens (#212)
by Arnout Engelen
· 8 weeks ago
23b08e0
feat: poor man's token auth (#211)
by Arnout Engelen
· 3 months ago
ea23c5c
mount postfix drop dir
by Arnout Engelen
· 3 months ago
5d8f62c
test instance of vulnogram
by Arnout Engelen
· 3 months ago
263e44d
Bump github/codeql-action from 3 to 4 (#206)
by dependabot[bot]
· 3 months ago
main-backup2
189396b
Bump actions/checkout from 6 to 7 (#208)
by dependabot[bot]
· 3 months ago
d68fb40
deployment: support deploying new version as pipservice (#207)
by Arnout Engelen
· 4 months ago
633a77d
Merge remote-tracking branch 'origin/main-next' into main-next
by Arnout Engelen
· 4 months ago
11aab0d
Merge remote-tracking branch 'origin/main' into main-next
by Arnout Engelen
· 4 months ago
a0bb720
conf: superset has a security list
by Arnout Engelen
· 4 months ago
61b2437
Merge pull request #198 from apache/infrastructure-ruleset-bot/default-branch-protection
by Arnout Engelen
· 4 months ago
2d33f36
improve logout flow
by Arnout Engelen
· 4 months ago
12e7ca5
orc and spark have retired their security lists
by Arnout Engelen
· 4 months ago
e3c83a1
Set up default protection ruleset for default and release branches
by The Apache Software Foundation
· 5 months ago
infrastructure-ruleset-bot/default-branch-protection
77cee12
Merge pull request #183 from raboof/unittests
by Arnout Engelen
· 5 months ago
cbe31d4
Merge pull request #196 from raboof/update-oauth
by Arnout Engelen
· 5 months ago
a5f37b4
Expand OAuth implementation
by Arnout Engelen
· 5 months ago
a710c6c
remove CVE portal from sidebar
by Arnout Engelen
· 5 months ago
2660f1e
fix and run unit tests
by Arnout Engelen
· 5 months ago
cad7996
Merge pull request #176 from raboof/integrate-upstream-changes
by Arnout Engelen
· 5 months ago
main-backup
8ce80a3
Merge branch 'main' into integrate-upstream-changes
by Piotr P. Karwasz
· 5 months ago
567651b
feat: improve testability of Vulnogram (#194)
by Piotr P. Karwasz
· 5 months ago
4f1aca4
serverity level validation
by Arnout Engelen
· 5 months ago
fcb5b3e
enable packageURL field
by Arnout Engelen
· 5 months ago
5f7ecce
Merge remote-tracking branch 'upstream/1.0.3' into integrate-upstream-changes
by Arnout Engelen
· 5 months ago
cd81898
Merge remote-tracking branch 'origin/main' into integrate-upstream-changes
by Arnout Engelen
· 5 months ago
3a0ce91
Merge remote-tracking branch 'upstream/1.0.2' into integrate-upstream-changes
by Arnout Engelen
· 5 months ago
184ccb9
Bump actions/checkout from 2 to 6 (#192)
by dependabot[bot]
· 5 months ago
767dcdc
Fix and simplify CodeQL action (#190)
by Piotr P. Karwasz
· 5 months ago
f0daa30
Fix `dependabot.yml` syntax
by Piotr P. Karwasz
· 5 months ago
f9b3852
simplify message
by Chandan
· 5 months ago
38d73e2
Bump CodeQL to version 3
by Piotr P. Karwasz
· 5 months ago
4743f6a
Try enabling Dependabot again
by Piotr P. Karwasz
· 5 months ago
1df7c1e
Disable Dependabot for NPM
by Piotr P. Karwasz
· 5 months ago
a25df36
Enable Dependabot (#188)
by Piotr P. Karwasz
· 5 months ago
5a603a4
Configure Dependabot for `github-actions` (#186)
by Piotr P. Karwasz
· 5 months ago
8d48b5a
Ignore IntelliJ IDEA/WebStorm files
by Piotr P. Karwasz
· 5 months ago
8396f85
chore: restrict codeql CI permissions (#185)
by Arnout Engelen
· 5 months ago
c3759c8
CVE Transfer Feature
by Chandan
· 5 months ago
2bbedb5
Merge pull request #181 from raboof/asf-dev-mode
by Arnout Engelen
· 5 months ago
3700467
ASF: disable CVE and email in 'development' mode
by Arnout Engelen
· 5 months ago
9954795
AV icons
by Chandan
· 5 months ago
165d2b3
missing spaces in html to text and the start of <p>
by Chandan
· 5 months ago
1446fa6
Merge pull request #180 from raboof/allow-security-to-open-malformed-cves
by Jarek Potiuk
· 6 months ago
ba78ab3
Allow security team members to edit malformed CVEs
by Arnout Engelen
· 6 months ago
2f11bca
set current time on focus - seems like the best option to address Firefox's lack of time picker on datetime-local
by Chandan
· 6 months ago
22c231f
render improvements
by Chandan
· 6 months ago
f3ca093
Bug fixes, improve error bubble display, date rendering
by Chandan
· 6 months ago
e66194e
fix friendly date rendering
by Chandan
· 6 months ago
cc2ac3b
Bug fixes
by Chandan
· 6 months ago
1a7cd00
bug fixes, don't invert colors for some icons like logos
by Chandan
· 6 months ago
f96bbdf
fix loading isse when there was no session
by Chandan
· 6 months ago
f99dd54
Merge pull request #306 from Vulnogram/master
by Chandan
· 6 months ago
f7d2419
bug fixes
by Chandan
· 6 months ago
Next »