Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add an utility method on the advisory framework to fetch product identifiers #484

Closed
mpermar opened this issue Oct 25, 2023 · 0 comments · Fixed by #505
Closed

Add an utility method on the advisory framework to fetch product identifiers #484

mpermar opened this issue Oct 25, 2023 · 0 comments · Fixed by #505
Labels
enhancement New feature or request

Comments

@mpermar
Copy link

mpermar commented Oct 25, 2023

Vulnerability scanners will tipically grab a VEX assessment, look at each vulnerability status and then get the array of product ids. But those product ids are usually meaningless to scanners. They do need the product identifiers. And those identifiers might be deep in the CSAF product tree at different levels. So there is definitely always some tree navigation that needs to be done for being able to grab the purls, cpes, etc.

It would be nice if this library offered some way to fetch a list of purls for a given list of product identifiers. I have a naive PoC implementation here but it is only for PURLs. Ideally this should be abstract enough to support other identification mechanisms.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
2 participants