mirror of
https://github.com/Drop-OSS/drop.git
synced 2026-08-29 04:32:06 -04:00
Each entry has: id, title, package, advisory (GHSA), severity, affected_paths, mitigation, accepted_by, accepted_date, review_by (90 days from accept). When review_by passes, the entry must be re-evaluated: either fixed, accepted again with new review_by, or escalated. Initial entries: 1 critical (decompress, patched locally), 2 high (lodash.pick, svgo via tauri-inliner), 8 moderate, 2 low. All transitive through tauri-inliner or dev-only deps. No production-exploitable paths. |
||
|---|---|---|
| .. | ||
| risk-register.yaml | ||