-
Notifications
You must be signed in to change notification settings - Fork 9
Open
Labels
help wantedExtra attention is neededExtra attention is neededquestionFurther information is requestedFurther information is requested
Description
Originally I called this osv-detector because I felt "auditor" and "scanner" were a bit overloaded, and I was considering if this was to be published as a package somewhere, osv-detector would be less likely to have already been taken.
However, I'm now thinking if it would be better to call it something else for a few reasons:
I'm thinking about additional checks we could be doing, like Support checking if things are approaching EOL with endoflife.date #75(I don't think this is probably worth it)- Go packages/binaries are not restricted to unique names, and
osv-detectormight not be as easy to find as say "security-auditor" osv-detectoris sort of wrong, as this tool isn't for "detecting OSVs"...
But the real blocker for me is what to actually call it instead - I'd prefer to not use "lockfile" (e.g lockfile-auditor) because that'd put us back in the same place if we start auditing more than them (but then maybe it's fine?)
Metadata
Metadata
Assignees
Labels
help wantedExtra attention is neededExtra attention is neededquestionFurther information is requestedFurther information is requested