Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Extend Vulnerabilities check with https://github.com/github/advisory-database #1707

Closed
naveensrinivasan opened this issue Mar 3, 2022 · 4 comments

Comments

@naveensrinivasan
Copy link
Member

Is your feature request related to a problem? Please describe.
Scorecard does vulnerability scan with osv.dev. Recently GitHub OSS their Vulns https://github.com/github/advisory-database. It would be nice if scorecard can check with this DB for reporting any issues.

@naveensrinivasan naveensrinivasan added the kind/enhancement New feature or request label Mar 3, 2022
@naveensrinivasan
Copy link
Member Author

Related G-Rath/osv-detector#3

@G-Rath
Copy link

G-Rath commented Aug 25, 2022

@naveensrinivasan osv-detector is at a pretty good point now that I think it should be usable here - I'm wondering if it could be used as a binary to avoid having to duplicate all the manifest/lockfile finding stuff, and then scorecard could parse its json output. Would that work?

Copy link

github-actions bot commented Nov 2, 2023

This issue is stale because it has been open for 60 days with no activity.

@spencerschrock
Copy link
Contributor

This was implemented back in #2509 via osv-scanner, which has the GitHub Advisory Database

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants