[Epic] Add security scanner integration
Personne n'a encore pris cette issue.
- Langage dominant
- Python
- Étoiles
- 49
- Forks
- 88
- Merge moyen
- 1 j 10 h
- PR mergées (30 j)
- 31
Description
Original Pulp Redmine Issue: https://pulp.plan.io/issues/6872
Goal
Users storing content in pulp_python should derive benefit from security scanning of Python packages that are out there.
Existing Tools
The idea is to integrate a tool not make a new one. Here are some options I've read about from this article.
Scanning Python Code Itself
Scanning Python Dependencies
- safety <-- freemium model with limited updates when not paid for
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Start by reviewing the goal and the listed scanning options in this issue, then read the linked article and the Bandit, Pysa, and Safety documentation. Determine which tool and integration scope fit pulp_python; done means the selected scanner is integrated so users storing Python content can benefit from security scanning.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- python
- Domaine
- security
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- À l'abandon
- Clarté
- À clarifier
- Accessibilité débutants
- 20/100