aboutcode-org / aboutcode-org/fetchcode
Add FetchCode support for rpm
- 主要言語
- HTML
- スター
- 13
- フォーク
- 24
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
At first glance, you cannot derive a deterministic download URL for RPM packages from a PURL - even with qualifiers - because RPM ecosystems lack a centralized, standardized CDN like Alpine or Debian. RPMs are distributed across many vendor-specific, versioned, and dynamically updated repositories.
But in practice we can download RPMs alright so we need to try harder! The code is to be written alright, in PurlDB and FetchCode
See these places:
- https://github.com/aboutcode-org/purldb/blob/main/minecode/miners/repodata_rpms.py
- https://github.com/aboutcode-org/purldb/blob/main/minecode/miners/repodata.py
- https://github.com/aboutcode-org/purldb/blob/main/minecode/miners/repomd.py
- https://github.com/aboutcode-org/purldb/blob/main/minecode/miners/fedora.py
- https://github.com/aboutcode-org/vulnerablecode/blob/dcb0511c73283654ab8a4ca340b71d6d9c5a16b9/vulnerabilities/rpm_utils.py#L76
- https://github.com/aboutcode-org/scancode-toolkit/blob/develop/src/packagedcode/rpm.py
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。