Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss
When analyzing Windows and .NET applications, there are always a certain number of DLLs that are not found in NuGet packages but are provided by Microsoft as part of SDKs. There are also legacy code from codeplex or code from the codeproject
Therefore, it would be useful to collect common Microsoft SDKs and runtimes, and related so they can be indexed and matched such as these PURLs:
When analyzing Windows and .NET applications, there are always a certain number of DLLs that are not found in NuGet packages but are provided by Microsoft as part of SDKs. There are also legacy code from codeplex or code from the codeproject
Therefore, it would be useful to collect common Microsoft SDKs and runtimes, and related so they can be indexed and matched such as these PURLs:
Fake PURLs:
and their home and download URLs: