Coder Social home page Coder Social logo

ossaudit's People

Contributors

illikainen avatar sseide avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar

ossaudit's Issues

Need a way to reset a cache

I case of the index DB is updated (a vulnerability is fixed) the ossaudit tool uses the data from the cache and doesn't fetch new records.
To get new data I had to find and remove the cache.json file.
It would be great to have a flag --no-cache to ignore the data from cache.json or --reset-cache to rewrite the cache file.

No package version in requirements.txt defaults to version 0

I have a situation where developers have a requirements.txt file but none of the packages have a version. While this is allowed by pip, it has resulted in false positives because pip grabs the latest version, but the scan is pulling vulnerability data for the 0 version. While I am trying to get our developers to add versions, which is a much better DevSecOps practice, there really should be a way for the OssIndex scan to use the latest version for the scan as this is what pip pulls in this case. Given the recent dependency confusion attack, this and warning on no version would be huge helps.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.