google / google/osv.dev

OSV.dev downstream users have a way to reason about records that are absent from OSV.dev because of failure to meet the minimum quality bar

Open
#2,190 1 comment 0 reactions 0 assignees View on GitHub
backlog
Dominant language
Go
Stars
2.9k
Forks
369
Avg merge
1d 17h
Merged PRs (30d)
149

Description

# Problem statement

An OSV.dev user searching for a specific record by ID (either by using the shortcut URL OSV.dev/{identifier} or by searching for it from https://osv.dev/list cannot determine if the failure to find it is because the home database hasn't published it, or if the record has failed to meet OSV.dev's quality bar.

# Desired outcome

When a user searches for a record that is known to OSV.dev (either because it exists and has been imported, or exists and OSV.dev has declined to import it) they receive situation-appropriate feedback/behaviour from OSV.dev

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.