Add standard "known vulnerabilities" metadata field, sourced from OSV
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 45/100
Rechercherichtung
Start with PythonRepositoryVersionViewSet and the existing VulnerabilityReport.vulns data, then compare the response-shape precedent in #1282 for PackageYank. The work is done when Simple API and JSON API responses expose the standard vulnerabilities field from OSV results, with the issue's open question about automatic scanning resolved.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Is your feature request related to a problem? Please describe.
pulp_python already has vulnerability-scanning capability: a scan action on PythonRepositoryVersionViewSet (added in #1013/#1012) queries OSV.dev and stores results in pulpcore's VulnerabilityReport model. However, that data is not exposed through the standard PyPI "known vulnerabilities" metadata field described in the PyPI JSON API spec — the existing scan output lives in its own report resource, not in the Simple API / JSON API response shape that standard PyPI tooling expects, and today's scan is manual/on-demand only. Tooling that relies on the standard field for vulnerability visibility (e.g. Red Hat Trusted Libraries / the pulp-trustify effort) has no way to consume it from pulp_python today.
Describe the solution you'd like
Surface the existing VulnerabilityReport.vulns data (see above) through the Simple API / JSON API responses as the standard vulnerabilities field, following a comparable per-(name, version) marker pattern to native PackageYank support (#1282) for the API-shape/serializer side. OSV remains the data source underneath — no new scanning backend needed. Open design question to resolve here: scanning today is manual/on-demand only — deciding whether it should also trigger automatically (e.g. on sync/upload) is in scope for this issue.
This is agreed phase-1 scope for the Pulp-Trustify integration effort — complex/custom scanning and Trustify-specific data-source integration are intentionally deferred to a later phase (see context below).
Describe alternatives you've considered
- Implementing this in
pulp-serviceinstead — ruled out;pulp-service(the hosted Pulp team) is an external stakeholder for this effort, not a place for this logic to live. - Full Trustify-backed scanning/library integration now — deferred; this issue is scoped narrowly to the standard OSV-sourced
vulnerabilitiesfield, decoupled from the broaderpulp-trustifycore-library work happening in parallel in pulp/pulp_trustify. - Building a new scanning mechanism from scratch — ruled out; #1013/#1012 already added an OSV.dev-backed scan pipeline (
VulnerabilityReportmodel,scanaction) that this issue should extend rather than duplicate.
Additional context
- Part of the broader Trustify integration program (Red Hat Trusted Libraries / Calunga); tracked upstream at pulp/pulp_trustify.
- Related PRs: #1013/#1012 (existing OSV.dev-backed scan pipeline —
VulnerabilityReportmodel,scanaction — the mechanism this issue extends), #1282 (nativePackageYankcontent model — API-shape precedent for surfacing a per-package marker). - Filed on behalf of Otávio Fernandes; Gerrod Ubben to be notified separately once this is actually filed — he may pick it up next sprint, or review a contribution from Otávio.
- Vorherrschende Sprache
- Python
- Sterne
- 49
- Forks
- 88
- Ø Merge
- 2 T. 4 Std.
- Gemergte PRs (30 T.)
- 31
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus pulp/pulp_python
-
Feature Triage-Needed
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 45/100
pulp/pulp_python#1371 · 2 Reaktionen ·
Maintainer antworten meist innerhalb von 1 Tag
-
Extension of Python REST API (repo index)Evtl. vergeben @TenSt hat das vor 40 Tagen übernommen. Offen
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 52/100
pulp/pulp_python#1358 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Add support for SLSA attestation verification (pulp-service patch 0048)Evtl. wieder frei @jobselko hat das vor 47 Tagen übernommen, und es ist kein Pull Request offen. OffenFeature
pulp/pulp_python#1340 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
-
Issue
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 58/100
pulp/pulp_python#1219 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Feature
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 25/100
pulp/pulp_python#1005 ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in pulp/pulp_python
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 83/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 86/100
FuRongJun-1999/dsh-memory#65 ·
Maintainer antworten meist innerhalb von 1 Tag
-
ci needs-ac
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
Ikalus1988/MisakaNet#2930 ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Qiskit/qiskit-aer#2466 ·
-
area/cli
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100