Skip to content

Commit e0f495c

Browse files
authored
Document limitations and future work in README
Added limitations and future work section to README.
1 parent 8a60052 commit e0f495c

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

README.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -368,6 +368,14 @@ You can tune concurrency and increase the delay to reduce the chance of hitting
368368

369369
Each time a secondary rate limit is hit, the delay between fetching SBOMs is increased by 10%, to provide a way to adaptively respond to that rate limit.
370370

371+
## Limitations & future work
372+
373+
- Only malware advisories are synchronised from the GitHub Advisory Database, by design
374+
- future work could allow synchronising from other compatible vulnerability databases to match additional ecosystems to those in the GHADB
375+
- Semver matching is used for all ecosystems, which may not work correctly
376+
- There is no continuous running mode - it runs as a one-off at the command line
377+
- future work could allow running in a Docker container in this manner
378+
371379
## 🤝 Contributing
372380

373381
Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) for details on how to contribute to this project.

0 commit comments

Comments
 (0)