Make vulnerabilities links
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 68/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- html
- Domain
- frontend
Research direction
Start by locating the vulnerability rendering entry point and the code that displays source, reference, and advisory URLs. Trace how vulnerability IDs and URLs are currently output, then verify valid links, safe handling of malformed URLs, HTML encoding, and new-tab behavior against the acceptance criteria.
Written by the indexing model from the issue text.
Description
Feature Request: Render Vulnerability URLs as Clickable Links
Problem
When vulnerability information from a CycloneDX SBOM is displayed, the vulnerability URLs are currently rendered as plain text.
For example, a vulnerability contains a source URL such as:
"source": {
"name": "github-language-dotnet",
"url": "https://github.com/advisories/GHSA-6xh7-4v2w-36q6"
}
It may also contain additional URLs in the references and advisories collections.
Users must currently copy and paste these URLs into a browser to view the corresponding advisory.
Requested Behavior
Render vulnerability URLs as clickable hyperlinks wherever they are displayed.
At minimum, the following fields should be linked:
vulnerabilities[].source.urlvulnerabilities[].references[].source.urlvulnerabilities[].advisories[].url
When a vulnerability ID is displayed, such as GHSA-6xh7-4v2w-36q6, the ID could use vulnerabilities[].source.url as its hyperlink rather than displaying the full URL separately.
Example
Instead of displaying:
GHSA-6xh7-4v2w-36q6
https://github.com/advisories/GHSA-6xh7-4v2w-36q6
Display the vulnerability ID as a link:
[GHSA-6xh7-4v2w-36q6](https://github.com/advisories/GHSA-6xh7-4v2w-36q6)
Additional advisory links should also be clickable.
Acceptance Criteria
- Valid HTTP and HTTPS vulnerability URLs are rendered as hyperlinks.
- Clicking a vulnerability ID opens its primary source URL.
- URLs in the
referencesandadvisoriescollections are also clickable. - Links open in a new browser tab or window.
- Link text clearly identifies the advisory, preferably using the vulnerability or advisory ID.
- Malformed or unsupported URLs continue to display safely as plain text.
- URLs and link text are HTML-encoded to prevent injection vulnerabilities.
- Dominant language
- HTML
- Stars
- 125
- Forks
- 16
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from CycloneDX/Sunshine
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 72/100
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 38/100
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 25/100
All issues in CycloneDX/Sunshine
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
godotengine/godot-website#1432 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
getgrav/grav-theme-quark2#26 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
SocialGouv/egapro#4672 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
-
🐞 bug 🧐 unconfirmed
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Tencent/tdesign-miniprogram#4664 · 1 comment ·
Maintainers usually reply within 1 day