-
Hi,
Today, the database only have one purl matching one cpe with all its different versions. So for exemple `pkg:github/wp-plugins/simple-banner` will have the following cpe:
- `cpe:2.3:a:simpl…
-
PURL: pkg:maven/com.google.protobuf/protobuf-java
Query Command:
select cpe from purl2cpe where purl = 'pkg:maven/com.google.protobuf/protobuf-java';
-
https://github.com/nexB/purl2cpe and https://github.com/sbs2001/purl2cpe have long been using this name. Please try to find another name for your project to avoid confusion, even if the purpose are si…
-
For example, look at purl2cpe/data/libav/libav/purls.yml
`pkggithub/libav/libav` is not correct. That shouldn't pass the most basic check.
I've processed the entire repo and there are thousands…
-
As much as I'm sure we'd all like to see CPE's go away, it seems unlikely at this point and I think it'd be useful to help with mapping existing CPE-based data to something more useful.
Should we …
-
As [discussed as part of the PURL spec](https://github.com/package-url/purl-spec/issues/138), we cannot have a generic CPE PURL mapping and need to track CPEs separately for the time being. Which als…