l3montree-dev / l3montree-dev/devguard

Canonical VEX information

Open
#2,790 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

feature-request
Dominant language
Go
Stars
161
Forks
43
Avg merge
1d 8h
Merged PRs (30d)
37

Description

For images and applications based on Ubuntu runtimes it would be great if the VEX information published by Canonical (https://ubuntu.com/security/vex) would be available in DevGuard.

If syncing them into the DevGuard database is not possible or a bad idea it would be nice to have an easy way to manually import the VEX information

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing Canonical's VEX publication at https://ubuntu.com/security/vex; the issue names no DevGuard files, tests, or entry points. Decide whether automatic database syncing or a manual import is the intended scope, with Ubuntu-runtime VEX information available in DevGuard as the completion criterion.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, ubuntu
Domain
backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.