Make vulnerabilities links
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 68/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- html
- Domain
- frontend
Research direction
Start by locating the vulnerability rendering entry point and the code that displays source, reference, and advisory URLs. Trace how vulnerability IDs and URLs are currently output, then verify valid links, safe handling of malformed URLs, HTML encoding, and new-tab behavior against the acceptance criteria.
Written by the indexing model from the issue text.
Description
Feature Request: Render Vulnerability URLs as Clickable Links
Problem
When vulnerability information from a CycloneDX SBOM is displayed, the vulnerability URLs are currently rendered as plain text.
For example, a vulnerability contains a source URL such as:
"source": {
"name": "github-language-dotnet",
"url": "https://github.com/advisories/GHSA-6xh7-4v2w-36q6"
}
It may also contain additional URLs in the references and advisories collections.
Users must currently copy and paste these URLs into a browser to view the corresponding advisory.
Requested Behavior
Render vulnerability URLs as clickable hyperlinks wherever they are displayed.
At minimum, the following fields should be linked:
vulnerabilities[].source.urlvulnerabilities[].references[].source.urlvulnerabilities[].advisories[].url
When a vulnerability ID is displayed, such as GHSA-6xh7-4v2w-36q6, the ID could use vulnerabilities[].source.url as its hyperlink rather than displaying the full URL separately.
Example
Instead of displaying:
GHSA-6xh7-4v2w-36q6
https://github.com/advisories/GHSA-6xh7-4v2w-36q6
Display the vulnerability ID as a link:
[GHSA-6xh7-4v2w-36q6](https://github.com/advisories/GHSA-6xh7-4v2w-36q6)
Additional advisory links should also be clickable.
Acceptance Criteria
- Valid HTTP and HTTPS vulnerability URLs are rendered as hyperlinks.
- Clicking a vulnerability ID opens its primary source URL.
- URLs in the
referencesandadvisoriescollections are also clickable. - Links open in a new browser tab or window.
- Link text clearly identifies the advisory, preferably using the vulnerability or advisory ID.
- Malformed or unsupported URLs continue to display safely as plain text.
- URLs and link text are HTML-encoded to prevent injection vulnerabilities.
- Dominant language
- HTML
- Stars
- 125
- Forks
- 16
- PR merge metrics
- No merged PRs in 30d
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CycloneDX/Sunshine
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 72/100
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 38/100
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 25/100
All issues in CycloneDX/Sunshine
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
openedx/frontend-app-authoring#3274 ·
Maintainers usually reply within 1 day
-
Unconfirmed bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
luanti-org/luanti#17605 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
microsoft/fluentui-blazor#5364 ·
Maintainers usually reply within 1 day
-
COLEAD websiteOpenneeds-triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
wagtail/madewithwagtail#236 · 1 comment ·
Maintainers usually reply within 4 days
-
Design only Leadership Survey SLFS
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
bcgov/digital-journeys#2293 ·