aboutcode-org / aboutcode-org/vulnerablecode

Better track and document ignored versions

未關閉
#737 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

Some data source or ecosystems have weird stuff. We are for now tracking some of these as ignoreable version for instance in the GitHub Importer.

The more I see these ignorable_versions and in particular the list of "WEIRD_IGNORABLE_VERSIONS," the more I think this is smelling bad or weird. IMHO we should rather have this approach:
- An ignorable versions should be tied to a specific package URL, and not freestanding
- Ideally it would be an IgnorableVersion object with a purl attribute, a list of ignorable versions AND a reason text that explains why we are ignoring these.
- When using these, we should only ignore things IFF we have a proper matching purl so that we are super restrictive about the context.
- In some case we may even consider still importing these invalid data but mark them as as invalid, not usable somehow with some falf in the models.

Otherwise, I feel we are likely to skip things silently and that's a problem.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。