Don't remove links from Dependabot alert descriptions #39855
Unanswered
glye
asked this question in
Code Security
Replies: 2 comments 1 reply
-
|
Hi there @glye and welcome to our community! Thank you for the feedback! |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
👋 PM for Dependabot Alerts here. I've spoken with our Advisory Curation team. Are you referring to this advisory from two weeks ago? The curation team added some additional context to the description and published it here! |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Product Feedback
Body
Security advisory descriptions can contain various text including links. When Dependabot alerts are created from an advisory, their description contains mostly the same text as the advisory, but the links are edited out. This leads to loss of information to users. It can be crucial for understanding the risks the alert is warning about.
The best would be to include the links, but if this won't be done the advisory editing UI should inform about this when links are inserted there, and advisory documentation should mention it.
Beta Was this translation helpful? Give feedback.
All reactions