Impact Analysis

Use when determining which portfolio repositories are affected by an advisory (CVE, GHSA, MAL-/malicious-package, or another OSV-native id). Queries the portfolio graph for blast radius, then runs language-specific analysis (govulncheck + ELF reachability for Go, the strongest tier; manifest-level analyzers for npm, PyPI, Maven, Cargo, RubyGems, and NuGet; a manifest-level SurfaceAnalyzer for the universal Docker/GitHub Actions/Helm surfaces) to classify every importing repo. Emits a schema-validated artifact consumed by /triage and /verify-remediation.

openshift ee73d97 2 files · 20.9 KB Updated

File contents

openshift/traust/tree/main/harnessing/3-audit/impact-analysis commit ee73d971d1

Frequently asked questions

npx skillmds@latest add openshift/impact-analysis