[Epic] Add security scanner integration
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- Python
- Estrellas
- 49
- Forks
- 88
- Merge medio
- 1 d 10 h
- PR fusionados (30 d)
- 31
Descripción
Original Pulp Redmine Issue: https://pulp.plan.io/issues/6872
Goal
Users storing content in pulp_python should derive benefit from security scanning of Python packages that are out there.
Existing Tools
The idea is to integrate a tool not make a new one. Here are some options I've read about from this article.
Scanning Python Code Itself
Scanning Python Dependencies
- safety <-- freemium model with limited updates when not paid for
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Start by reviewing the goal and the listed scanning options in this issue, then read the linked article and the Bandit, Pysa, and Safety documentation. Determine which tool and integration scope fit pulp_python; done means the selected scanner is integrated so users storing Python content can benefit from security scanning.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- python
- Área
- security
- Tipo de issue
- Nueva funcionalidad
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Estado de actividad
- Estancado
- Claridad
- Necesita aclaración
- Aptitud para principiantes
- 20/100