loopbackio / loopbackio/security
Produce GitLab-format security advisories
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 4
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
This issue is to keep track producing of security advisories in the GitLab format.
Reasons for producing GitLab-format security advisories:
- Provides single source of truth
- Allows for mapping validation with CSAF
- Allows ease of pushing updates of security advisories to the GitLab Advisory Database
Currently, this is blocked by the JSON Schema not being licensed under a standard FOSS license. We have raised the issue with GitLab: https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/issues/186#note_867769170
This issue is no longer blocked.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Start by locating how this repository currently represents or produces security advisories, then determine the GitLab format and CSAF mapping requirements; done means GitLab-format advisories can be produced and updates can be pushed to the GitLab Advisory Database.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- gitlab, json
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100