Can build tags be supported as part of version ranges for fix present or not?
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 370
- Forks
- 111
- Avg merge
- 3h 52m
- Merged PRs (30d)
- 4
Description
at times one can re-vendor a newer shared library dependency to effectively address a CVE. In such cases one can increase a build number; whilst keeping the wheel version the same.
Some of this was already touched in https://github.com/pypa/advisory-database/issues/103
I wonder if the database here or in osv can support build tags as part of the version stream?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the linked advisory-database issue 103 and comparing how this database and OSV represent version ranges. Determine whether Python wheel build tags can be expressed in the existing advisory model; done requires a documented decision and, if supported, a defined representation and validation path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- databases, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100