aboutcode-org / aboutcode-org/vulnerablecode

Consider removing PYSEC importer and keep PYPA importer only

未关闭
#2,327 3 条评论 0 个 reaction 已指派 1 人 已被 @TG1999 认领 在 GitHub 查看
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pypa_importer.py
- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pysec_importer.py

Currently we have both importers and they are potentially importing same data, we need to verify and remove pysec_importer since pypa_importer provides more better and closer source like this:

- https://github.com/pypa/advisory-database/blob/main/vulns/aamiles/PYSEC-2022-43066.yaml

Whereas pysec provides a zip URL only

https://osv-vulnerabilities.storage.googleapis.com/PyPI/all.zip

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。