with one click
update-vulndb
// Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.
// Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.
Update project documentation when features are added or changed. Use after modifying CLI commands, OPA rules, MCP tools, or the development workflow.
Run code formatting and linting after writing or modifying Go code. Use this after making code changes to ensure quality standards are met.
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
| name | update-vulndb |
| description | Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository. |
| disable-model-invocation | true |
| allowed-tools | Bash(make update-vulndb:*), Bash(make test:*) |
Update the embedded build platform vulnerability database:
make update-vulndbmake testNote: This clones the CVE repository (sparse checkout) and processes CVE JSON files for GitHub Actions and GitLab CI vulnerabilities. The output is written to opa/rego/external/build_platform.rego.