pulp / pulp/pulp_python

[Epic] Add security scanner integration

Offen
#349 1 Kommentar 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

feature request help wanted
Vorherrschende Sprache
Python
Sterne
49
Forks
88
Ø Merge
1 T. 10 Std.
Gemergte PRs (30 T.)
31

Beschreibung

Original Pulp Redmine Issue: https://pulp.plan.io/issues/6872

Goal

Users storing content in pulp_python should derive benefit from security scanning of Python packages that are out there.

Existing Tools

The idea is to integrate a tool not make a new one. Here are some options I've read about from this article.

Scanning Python Code Itself
Scanning Python Dependencies
  • safety <-- freemium model with limited updates when not paid for

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Start by reviewing the goal and the listed scanning options in this issue, then read the linked article and the Bandit, Pysa, and Safety documentation. Determine which tool and integration scope fit pulp_python; done means the selected scanner is integrated so users storing Python content can benefit from security scanning.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
20/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.