vulnerablecode icon indicating copy to clipboard operation
vulnerablecode copied to clipboard

add-curl-advisories-importer

Open ambuj-1211 opened this issue 1 year ago • 5 comments

This PR fixes #1166. The test file is a dummy and will be completed once the curl.py importer is completed.

ambuj-1211 avatar Jan 25 '24 11:01 ambuj-1211

@ambuj-1211 additionally please sign-off your commits

TG1999 avatar Jan 25 '24 14:01 TG1999

@TG1999 Apologies for the late response, I was stuck in my end sem exams. Done some changes as mentioned. I also want to know what to do for pURL, as in what should be the type, package name, and other components of the purl and also the version range for curl is not defined in univers what to do for that?

ambuj-1211 avatar Jan 31 '24 17:01 ambuj-1211

type-generic namespace-domain name i.e curl.se name - name of the tool (curl, tiny-curl), version - as specified, download_url as qualifiers, so https://curl.se/download/curl-8.6.0.tar.gz this will be pkg:generic/curl.se/[email protected]?download_url=https://curl.se/download/curl-8.6.0.tar.gz

TG1999 avatar Feb 06 '24 11:02 TG1999

@ambuj-1211 try to collect all the versions of curl and commit a test to check with univers if all versions are effectively Semver Version

TG1999 avatar Feb 06 '24 12:02 TG1999

@TG1999 check if it needs any more changes. Completed the curl.py file and the test_curl.py file.

ambuj-1211 avatar Mar 01 '24 14:03 ambuj-1211

@TG1999 done the changes please review the commits

ambuj-1211 avatar Mar 10 '24 12:03 ambuj-1211

@ambuj-1211 hey, you are not planning to complete this after all?

pombredanne avatar Mar 26 '24 18:03 pombredanne

@pombredanne I made a new pr regarding this issue therefore I closed this one, because there were some problems with this branch which I was not able to resolve.

ambuj-1211 avatar Mar 28 '24 08:03 ambuj-1211