transparency-exchange-api
transparency-exchange-api copied to clipboard
Add option for TEA service in security insights
https://github.com/ossf/security-insights-spec
Nice finding! :100:
I think that there are many concepts that should be coordinated/synchronized between TEA and the Security Insights Specification.
By looking rapidly at the specification:
- It is not clear to me what is the TEA object corresponding to
project. Since the SIS project has avulnerability-reporting.reports-acceptedproperty and major versions of a project can drop security support at different times, I think that SIS project corresponds to TEA product (Acme 1.x, Acme 2.x, etc.). - The SIS
repositoryon the other hand seems to correspond to a property of a TEA leaf