OSSIndex / vulns

Report missing advisories and corrections on OSS Index
17 stars 12 forks source link

Multiple issues with Drupal ecosystem support #149

Open RoSk0 opened 3 years ago

RoSk0 commented 3 years ago

I'm happy to split this issue if that would help and provide as much information/guidance/help as necessary to improve Drupal ecosystem support by OSS index.

RoSk0 commented 3 years ago

Drupal.org issue to expose fixed in version in advisory API properly https://www.drupal.org/project/drupalorg/issues/2966246 .

ken-duck commented 3 years ago

Thanks for the update. Up till now there has not been much interest in the Drupal data, so it has languished (as you noticed). We are going to approach this with a two-prong approach.

We are actually in the process of doing a major overhaul of all data collection systems for OSS Index. This is being phased in over time, "old" style Drupal packages are expected to be done by early to mid summer (all going well, maybe earlier if we are really lucky).

The "new" style, being packages in Composer, are further down the pipeline due to the sheer volume of data. In this case we can work on importing the drupal composer packages and matching applicable vulnerabilities in the older OSS Index data system to tide us over. This can be worked on over the next few weeks, and all going well we should start seeing results reasonably soon-ish.

We'll keep you updated as to progress so you can check it out and perhaps even help us make sure everything is being done correctly.

Thanks again.

RoSk0 commented 3 years ago

Thanks for sharing. Looking forwards for updates in this space.

RoSk0 commented 3 years ago

Hi @ken-duck ,

It there any news on Drupal support?