ossf / ossf/package-analysis

Add a check to ensure sandbox images are accessable before executing them.

Open
#346 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug good first issue
Dominant language
Go
Stars
912
Forks
74
PR merge metrics
No merged PRs in 30d

Description

The worker/analysis engine should ensure the sandbox images are all available at the start of execution.

This will help catch failures where a sandbox container image is unavailable, or if the environment has been configured incorrectly - and it will help prevent the pubsub messages from being consumed errantly.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the worker/analysis engine entry point that begins execution and the configuration for sandbox images. Determine how image availability can be checked before execution and how an unavailable or misconfigured image should stop processing. Done means unavailable sandbox images are detected before pubsub messages are consumed erroneously.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.