Skip to content

Run a package-only scan on a codebase as a new pipeline - Proactively scan and review all my packages #815

Description

@pombredanne

Following #720 and aboutcode-org/purldb#87 we need to have a pipeline that would only populate the packages and dependencies (and eventually later on also resolve dependencies)

The goal is to ensure that the purlDB is kept always up-to-date with the set of packages effectively used in a development codebase.

The overall process would be:

Separately I would like to have a way to determine if any of the package populated in the purlDB here has any license or origin issues based on data clarity and accuracy (using summaries, scores, --todo, package set, policies, compliance alerts, etc. and TBD )and I want to be alerted to review and eventually curate the issues that were uncovered, by exception.

Ideally there would be some minimal request/ticket system where a form would be posted for any item that would need further review. The ideal outcome would be to push and store a curated version of the package data (possibly in the purldB as part of a package set with a "curated" type) , or some ABOUT file that I could download to save in my codebase.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions