aboutcode-org / aboutcode-org/vulnerablecode

Conda-forge vulnerability advisories

オープン
#2,278 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

To infer vulnerability advisories for existing conda-forge packages, we need some smarts, as there are no such data source available that is open and public data.

Here is what we would need to do at a high level 
- resolve (jinja?) and parse the meta YAML for the 27K recipes. (Alternatively, we can also use the "rendered recipe" as stored in a package archive. They are in the info folder of the packages and don't contain any Jinja tags anymore.
- infer a PURL using the packageurl-python library
- say for https://github.com/conda-forge/django-feedstock/blob/5d10012b77cf6c36b6360af593dfff81a2e341c2/recipe/meta.yaml#L9 ...
- infer using https://github.com/package-url/packageurl-python/blob/c7c7b46346eebcd86ec61d4ee7c6a84c3fe5fcc4/src/packageurl/contrib/url2purl.py#L317
- ideally store that upstream PURL in the conda-forge ... also while at it craft a conda-package PURL too, save it too
- using that PURL, lookup in vulnerablecode, get any vulnerability advisories, and get a fixed version if any https://public2.vulnerablecode.io/packages/v2/pkg:pypi/django@6.0.4 (or an API call, or direct data dump and so on)
- eventually also store that data in conda-forge for that version as  VEX/CSAF/OSV/CVE
- eventually also attach the conda-forge package to the CVE if there is such CVE @ mitre (best... conda-forge becomes a CNA @ mitre , also of GNA with GCVE)
- (rinse and repeat 27,000 times, mostly everyday or many times a day). That would a combo of VCIO importer and improver
- eventually push and publish at all the feedstocks?

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。