-
Notifications
You must be signed in to change notification settings - Fork 1
Feature/372 create converter for pip audit vulnerabilities #387
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feature/372 create converter for pip audit vulnerabilities #387
Conversation
ebdbe4a to
2d879d2
Compare
…f the included actions
…ed for the tool pip-audit
- The current implementation chain parses a CVE from the title. While we could initially send non-CVEs, the difficulty would lie in updating the subsequent code to accomodate that. - For more information, see #387 (comment)
ckunki
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
In general, the PR looks fine to me.
Thanks for addressing all the findings.
The only thing I'm still missing is a document about the strategy, the involved tools and formats incl. some references (links) to the places explaining more details or defining these items. As we needed quite some time clarifying these basic concepts I think, it's definitely worth having some documentation explaining the concepts to other readers or our future me's as well.
What do you think?
ckunki
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
see my comments on the design document.
Closes #372