Skip to content

Commit 60d4ebb

Browse files
seb-kwtimbastin
andauthored
Update CHANGELOG.md
Co-authored-by: Tim Bastin <38261809+timbastin@users.noreply.github.com> Signed-off-by: Sebastian Kawelke <66557440+seb-kw@users.noreply.github.com>
1 parent 748a16b commit 60d4ebb

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

CHANGELOG.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ All notable changes to this project will be documented in this file.
5454
- Admin instance settings — Endpoint and middleware to read and update instance-level settings; `DISABLE_ORG_CREATION` config option for single-organization deployments
5555
- OCI proxy hardening — SSRF protection for the public OCI dependency proxy; path-parameter validation; GitLab registry support; public kill switch via the `DisablePublicRequest` middleware
5656
- User-agent propagation — User agent threaded through controllers, services, and integrations (events, license decisions, Jira); `user_agent` column on the events table; MCP-server `CreateEvent` calls are tagged accordingly
57-
- Fixable CVSS counts in risk statistics; risk calculation uses the highest risk per CVE/PURL pair
57+
- Fixable CVSS counts in risk statistics; risk calculation uses the highest risk per CVE/PURL pair. This builds upon the QuickFix Algoritm (https://docs.devguard.org/explanations/supply-chain-security/transitive-vulnerability-path-analysis/)
5858
- Daemon pipeline timeout raised to 2 hours to surface stuck imports instead of blocking the queue
5959
- Integration tests for scoped SBOM scans with artifact-specific vulnerabilities
6060
- OpenTelemetry spans on vulndb `ImportRC` and `checkIfTokenIsValid`, including retry attributes

0 commit comments

Comments
 (0)