yoni
17894006b4
Keep an approved fix when only the PR text changes
2026-09-30 08:24:08 +00:00
Jonathan Singer
77bd5dade5
Require an explicit fix handoff for source-backed findings
2026-09-30 03:40:21 -04:00
yoni
2b413da544
Keep prepared candidates and staleness consistent across revisions
...
A report revision whose locations can no longer form a candidate now
still supersedes any recorded preparation instead of leaving a ready
result pointing at superseded locations.
Preparation results carry the candidate that was actually verified so
SARIF emits the anchor-corrected edits rather than comparing the stored
draft's digest against a re-anchored one.
2026-09-25 07:06:21 +00:00
alex s
4c1be22150
Let agents delete a vulnerability report they filed ( #1354 )
2026-09-23 17:25:23 -07:00
Ahmed Allam
355a8bb437
fix(reporting): move the git blame hint to the end of the tool description
2026-09-18 21:39:35 +03:00
Ahmed Allam
77a0cf839b
fix(reporting): make the git blame hint a casual inline note
2026-09-18 21:39:35 +03:00
alex s
22959a7ba6
feat(reporting): link HTTP exchange evidence ( #1281 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-09-09 07:50:23 -07:00
alex s
46cf2f52f3
report: add update_vulnerability_report so an agent can revise a filed finding ( #1210 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-09-01 13:07:17 -07:00
yoni-at-strix
717ffc8f4c
Isolate MCP connections per task and surface connection status in the UIs ( #1181 )
2026-08-27 14:10:44 -07:00
devin-ai-integration[bot]
391d81bea7
feat(agents): evidence discipline, and coverage as a first-class artifact ( #961 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-24 03:34:09 -07:00
Ahmed Allam
a46a60cf6a
feat(reporting): require contextual CVSS and usage evidence on dependency reports
2026-08-17 14:35:21 +03:00
Ahmed Allam
e442db9c93
Contextual CVSS as a full 8-metric breakdown, computed like a normal finding
2026-08-17 13:03:41 +03:00
Ahmed Allam
9c0d30a0d0
reporting: require the source-to-sink trace in reachability evidence, not just CVSS reasoning
2026-08-17 13:03:41 +03:00
Ahmed Allam
99e2d5d826
reporting: drop per-metric contextual CVSS reasoning, keep the summary
2026-08-17 13:03:41 +03:00
Ahmed Allam
310f310e28
feat(reporting): contextual CVSS environmental metrics on dependency reports
2026-08-17 13:03:41 +03:00
Ahmed Allam
b69af37cb2
feat(report): keep dependency findings from distinct manifests separate in dedupe
2026-08-06 02:20:46 +03:00
Ahmed Allam
72cb15a20a
feat(reporting): require repo-relative manifest_path on dependency CVE findings
2026-08-06 02:20:46 +03:00
Alex Schapiro
97336d53e4
feat(reporting): structured reachability evidence ladder for dependency CVE findings
2026-08-06 00:25:08 +03:00
devin-ai-integration[bot]
657aa5cbe6
feat(reporting): record transitive dependency chain on SCA findings ( #971 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-08-04 12:34:52 -07:00
devin-ai-integration[bot]
a87bfb4881
fix(reporting): require advisory_cvss for dependency findings + add SCA TUI renderer ( #753 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-07-12 17:31:49 -07:00
alex s
4537f33f11
Add dependency reporting fields ( #751 )
2026-07-12 15:30:33 -04:00