commit | 210378171e42ffd5008108b2b44176140a1e6d8e | [log] [tgz] |
---|---|---|
author | Adrià Vilanova Martínez <me@avm99963.com> | Mon Apr 10 19:52:07 2023 +0200 |
committer | Adrià Vilanova Martínez <me@avm99963.com> | Mon Apr 10 19:52:07 2023 +0200 |
tree | ccb2e1ab640523b23d8c15b661c3c742263d2a4e | |
parent | 6b1b2c7787a0fde7093c588c65f15d464adbf6de [diff] |
Add support for the PublishAt field The purpose of the field is to let users set a custom date when the report should be published. This overrides the default disclosure flow. Change-Id: I9e01c3f9dd558dc7d3641fc774dd12b3a5b60967
A bot which is responsible for managing the vulnerability reports published at https://iavm.xyz/b/vulnz.
The bot performs the following tasks:
The bot will search private (restricted) vulnerability reports and will do the following:
In all the calculations above, a grace period of 1 day is added (so in reality it's 31 days instead of 30, and Deadline + 1 day
instead of Deadline
).
The bot will add a comment to a vulnerability report 5 days before it is automatically disclosed as explained in the previous section.
//secret/
and download the service accounts credentials JSON file to //secret/credentials.json
..env.sample
file to .env
and edit it to your liking.make docker-prod
and docker-compose up -d
.