Skip to content

analyze-cve

Full Go CVE analysis workflow. Given a CVE identifier -- supplied directly, or resolved from a Jira ticket or JQL batch -- resolves and clones the affected repository, gathers vulnerability intelligence, analyzes codebase impact with govulncheck and call-graph reachability, generates a risk report, and optionally applies a fix and opens a GitHub pull request. Use when the user gives a CVE ID (CVE-YYYY-NNNNN), a Jira ticket (--jira=), or a JQL query (--jql=) for Go CVE triage; wants call-graph proof that a vulnerable function is reachable; or wants an automated fix and PR for a Go dependency vulnerability. Triggers on: 'analyze CVE', 'CVE impact', 'is this repo affected by CVE', 'Go vulnerability analysis', 'triage this Jira CVE ticket', 'fix this CVE and open a PR', or a bare CVE-YYYY-NNNNN identifier.

Plugin: compliance

Usage

/compliance:analyze-cve

Source

View plugins/compliance/skills/analyze-cve/SKILL.md on GitHub