aboutcode-org / aboutcode-org/dejacode

Enhancement request: a default purpose and default deployed on Packages

未关闭
#191 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
design needed enhancement PackageSet
主要语言
Python
星标
50
派生
27
平均合并
4 小时 51 分钟
30 天内合并 PR
11

描述

When doing vulnerability management, it would be useful to track a global, dataspace Package a default purpose and default deployment.

This is an important context item for vulnerability mitigation prioritization.

- For instance, the Python sphinx doc tool is a "tool" by default.
- Junit is for tests in Java by default, and not deployed by default.

Given a vulnerability that affects a package, its default deployment and default purpose matters as this context should lower the actual risk exposure for this vulnerability. This could be an important part of a policy. The same data could be further set at the product-package level and would override the global dataspace- or purldb-level attributes.

These data items could be fed from PurlDB, some can be inferred, a lot would be curated.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。