aboutcode-org / aboutcode-org/vulnerablecode

Better track and document ignored versions

Đang mở
#737 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Python
Star
702
Fork
328
Merge trung bình
3 ngày 8 giờ
Pull request đã merge (30 ngày)
3

Mô tả

Some data source or ecosystems have weird stuff. We are for now tracking some of these as ignoreable version for instance in the GitHub Importer.

The more I see these ignorable_versions and in particular the list of "WEIRD_IGNORABLE_VERSIONS," the more I think this is smelling bad or weird. IMHO we should rather have this approach:
- An ignorable versions should be tied to a specific package URL, and not freestanding
- Ideally it would be an IgnorableVersion object with a purl attribute, a list of ignorable versions AND a reason text that explains why we are ignoring these.
- When using these, we should only ignore things IFF we have a proper matching purl so that we are super restrictive about the context.
- In some case we may even consider still importing these invalid data but mark them as as invalid, not usable somehow with some falf in the models.

Otherwise, I feel we are likely to skip things silently and that's a problem.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.