aboutcode-org / aboutcode-org/vulnerablecode

Consider removing PYSEC importer and keep PYPA importer only

Open
#2,327 3 comments 0 reactions 1 assignee Claimed by @TG1999 View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pypa_importer.py
- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pysec_importer.py

Currently we have both importers and they are potentially importing same data, we need to verify and remove pysec_importer since pypa_importer provides more better and closer source like this:

- https://github.com/pypa/advisory-database/blob/main/vulns/aamiles/PYSEC-2022-43066.yaml

Whereas pysec provides a zip URL only

https://osv-vulnerabilities.storage.googleapis.com/PyPI/all.zip

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.