snyk/vulncost

click to fix - not working on tap pkg

remy opened this issue · 2 comments

remy commented

Screenshot 2020-04-30 at 17 09 32

Two points here:

  1. Clicking didn't do anything, I had to go away from the decoration and to the 'tap' line, hover, open menu, then select 'fix'.
  2. From there, it says there's no rememdiation available - so it can't actually be fixed.

One other issue is that "fix vuln" shows even though a vulnerability is not fixable:
image

I'm happy to make a PR to fix this, but I'm not sure what it should say instead

Maybe "Remediation options"? I checked a few in my own repos, and it seems to provide some additional details (but less than the page at "Learn about this vulnerability") with either

  • "Possible remediation" with version candidates (including when there's a patch meant to fix the vuln) or
  • "No remediation available."

The extension already expects people to know the term "remediation" once they click on the button, so it's not introducing any new language complexity to use it here. It would also still be shorter than the following text string, so space shouldn't be an issue.