Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Gather feedback on reported vulnerabilities #201

Open
adamjanovsky opened this issue May 4, 2022 · 3 comments
Open

Gather feedback on reported vulnerabilities #201

adamjanovsky opened this issue May 4, 2022 · 3 comments
Assignees
Labels
enhancement New feature or request web Stuff related to the web at seccerts.org

Comments

@adamjanovsky
Copy link
Collaborator

It would be great if we could design vulnerability notifications in a way that encourages the recipient to evalute the risks and label our finding either as true positive or false positive. This would allow us to polish the classifiers, it also collects precious labeled instances.

@J08nY, could we somehow incorporate it into the notification system?

@adamjanovsky adamjanovsky added enhancement New feature or request web Stuff related to the web at seccerts.org labels May 4, 2022
@J08nY
Copy link
Member

J08nY commented May 5, 2022

Ugh, okay this is doable although it may be a lot of work. I am just now slowly getting the notifications to work, it is not easy to render the certificate changes and get the information about the changes from the diffs. But I guess to get a good user experience we have to have that and adding this feedback on top is not that hard.

@adamjanovsky
Copy link
Collaborator Author

Just a quick thought here. Maybe we could just add some line into the notification mail: dismiss as false positive or something like that... That could actually visit a link that would report us.

@J08nY
Copy link
Member

J08nY commented Oct 19, 2022

For sure, but as notifications are not even enabled on the site right now and wont be for the foreseeable future (we have to figure out a way to send email from the university network which is wicked limited) I view this as a low priority thing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request web Stuff related to the web at seccerts.org
Projects
None yet
Development

No branches or pull requests

2 participants