Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add MetaData Field for Remediation? #472

Open
josepalafox opened this issue Aug 21, 2020 · 1 comment
Open

Add MetaData Field for Remediation? #472

josepalafox opened this issue Aug 21, 2020 · 1 comment

Comments

@josepalafox
Copy link

Companies like Checkmarx offer tools like https://free.codebashing.com/ and other companies like https://securecodewarrior.com/ also work in this space.

I'm curious if the standard would consider supporting a metadata field that could link a user to resources to learn about how to remediate the vulnerability. For example if a SAST tool identifies a certain CWE error like SQL injection and then links the user to a resource like this: https://free.codebashing.com/courses/java/lessons/sql_injection.

@PatMyron
Copy link

PatMyron commented Sep 27, 2021

curious if the standard would consider supporting a metadata field that could link a user to resources to learn about how to remediate the vulnerability

or SARIF tooling could auto-remediation findings directly through metadata

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants