aboutcode-org / aboutcode-org/vulnerablecode
Consider removing PYSEC importer and keep PYPA importer only
- 主要言語
- Python
- スター
- 702
- フォーク
- 328
- 平均マージ
- 3日 8時間
- マージ済み PR(30日)
- 3
説明
- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pypa_importer.py
- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pysec_importer.py
Currently we have both importers and they are potentially importing same data, we need to verify and remove pysec_importer since pypa_importer provides more better and closer source like this:
- https://github.com/pypa/advisory-database/blob/main/vulns/aamiles/PYSEC-2022-43066.yaml
Whereas pysec provides a zip URL only
https://osv-vulnerabilities.storage.googleapis.com/PyPI/all.zip
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。