Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enhancement request: a default purpose and default deployed on Packages #191

Open
pombredanne opened this issue Oct 31, 2024 · 0 comments
Open
Labels
design needed Design details needed to complete the issue enhancement New feature or request

Comments

@pombredanne
Copy link
Member

pombredanne commented Oct 31, 2024

When doing vulnerability management, it would be useful to track a global, dataspace Package a default purpose and default deployment.

This is an important context item for vulnerability mitigation prioritization.

  • For instance, the Python sphinx doc tool is a "tool" by default.
  • Junit is for tests in Java by default, and not deployed by default.

Given a vulnerability that affects a package, its default deployment and default purpose matters as this context should lower the actual risk exposure for this vulnerability. This could be an important part of a policy. The same data could be further set at the product-package level and would override the global dataspace- or purldb-level attributes.

These data items could be fed from PurlDB, some can be inferred, a lot would be curated.

@pombredanne pombredanne added enhancement New feature or request design needed Design details needed to complete the issue labels Oct 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
design needed Design details needed to complete the issue enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant