aboutcode-org / aboutcode-org/vulnerablecode

Consider removing PYSEC importer and keep PYPA importer only

未關閉
#2,327 3 則留言 0 個 reaction 已指派 1 人 已被 @TG1999 認領 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pypa_importer.py
- https://github.com/aboutcode-org/vulnerablecode/blob/main/vulnerabilities/pipelines/v2_importers/pysec_importer.py

Currently we have both importers and they are potentially importing same data, we need to verify and remove pysec_importer since pypa_importer provides more better and closer source like this:

- https://github.com/pypa/advisory-database/blob/main/vulns/aamiles/PYSEC-2022-43066.yaml

Whereas pysec provides a zip URL only

https://osv-vulnerabilities.storage.googleapis.com/PyPI/all.zip

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。