yoni
40efae8095
feat(reporting): accept code_locations on dependency reports
...
Supply-chain findings (ln_report/create_dependency_report) can now carry
the same code locations as regular findings: usage sites such as an
import or call line (file/start_line/snippet/label) and optional
fix_before/fix_after proposed-change blocks (gated on fix_verification).
Locations go through the same normalization and validation as
create_vulnerability_report.
2026-09-25 05:36:35 +00:00
alex s
4c1be22150
Let agents delete a vulnerability report they filed ( #1354 )
2026-09-23 17:25:23 -07:00
Ahmed Allam
355a8bb437
fix(reporting): move the git blame hint to the end of the tool description
2026-09-18 21:39:35 +03:00
Ahmed Allam
77a0cf839b
fix(reporting): make the git blame hint a casual inline note
2026-09-18 21:39:35 +03:00
alex s
22959a7ba6
feat(reporting): link HTTP exchange evidence ( #1281 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-09-09 07:50:23 -07:00
alex s
46cf2f52f3
report: add update_vulnerability_report so an agent can revise a filed finding ( #1210 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-09-01 13:07:17 -07:00
yoni-at-strix
717ffc8f4c
Isolate MCP connections per task and surface connection status in the UIs ( #1181 )
2026-08-27 14:10:44 -07:00
devin-ai-integration[bot]
391d81bea7
feat(agents): evidence discipline, and coverage as a first-class artifact ( #961 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-24 03:34:09 -07:00
Ahmed Allam
a46a60cf6a
feat(reporting): require contextual CVSS and usage evidence on dependency reports
2026-08-17 14:35:21 +03:00
Ahmed Allam
e442db9c93
Contextual CVSS as a full 8-metric breakdown, computed like a normal finding
2026-08-17 13:03:41 +03:00
Ahmed Allam
9c0d30a0d0
reporting: require the source-to-sink trace in reachability evidence, not just CVSS reasoning
2026-08-17 13:03:41 +03:00
Ahmed Allam
99e2d5d826
reporting: drop per-metric contextual CVSS reasoning, keep the summary
2026-08-17 13:03:41 +03:00
Ahmed Allam
310f310e28
feat(reporting): contextual CVSS environmental metrics on dependency reports
2026-08-17 13:03:41 +03:00
Ahmed Allam
b69af37cb2
feat(report): keep dependency findings from distinct manifests separate in dedupe
2026-08-06 02:20:46 +03:00
Ahmed Allam
72cb15a20a
feat(reporting): require repo-relative manifest_path on dependency CVE findings
2026-08-06 02:20:46 +03:00
Alex Schapiro
97336d53e4
feat(reporting): structured reachability evidence ladder for dependency CVE findings
2026-08-06 00:25:08 +03:00
devin-ai-integration[bot]
657aa5cbe6
feat(reporting): record transitive dependency chain on SCA findings ( #971 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-04 12:34:52 -07:00
devin-ai-integration[bot]
a87bfb4881
fix(reporting): require advisory_cvss for dependency findings + add SCA TUI renderer ( #753 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-07-12 17:31:49 -07:00
alex s
4537f33f11
Add dependency reporting fields ( #751 )
2026-07-12 15:30:33 -04:00