aboutcode-org / aboutcode-org/vulnerablecode

Make VulnerableCode less fragile to schema changes in upstream projects

オープン
#272 コメント 5 件 リアクション 0 件 担当者 0 名 GitHub で見る
Data collection feature
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

This is related to https://github.com/nexB/vulnerablecode/issues/266 and https://github.com/nexB/vulnerablecode/issues/244 .

Currently we use schema validators like https://github.com/nexB/vulnerablecode/blob/40fe93611703cd37eb18e72bf2c9c747e5da1863/vulnerabilities/importers/debian.py#L44 . The rationale I had behind using it was to have loud failures and prevent VulnerableCode to insert garbage data into db .

The next step would be to evolve this mechanism in addition to prevent inserting garbage data, we want it to be:
1. Greedy wrt to collection of data. IE don't stop at first failure. It should rather navigate around failures.
2. Have robust error logging and handling. Currently we seriously lack this.
3. Have periodic import tests. For this periodic GitHub actions would be used. Each importer will have it's own action so as to compartmentalize individual importer failure. We could even have their status in our README.

Regarding GitHub actions, these need to be quickly finished. We can do this by only running the "gather" process in the actions. Don't run the "insert" process in the action.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。