conda-incubator / conda-store

Data science environments, for collaboration. ✨
https://conda.store
BSD 3-Clause "New" or "Revised" License
144 stars 49 forks source link

Flag environments with packages listed as CVE #293

Open pierrotsmnrd opened 2 years ago

pierrotsmnrd commented 2 years ago

The goal is to offer features based on the CVE detection. Before coding anything, we'll need to explore and scope.

  1. Identify a reliable source of CVE with an API we can use

  2. Define the features we want to add to Conda Store.

Examples (not a requirement list) :

pierrotsmnrd commented 2 years ago

Following up a discussion on slack : National Vulnerability Database https://nvd.nist.gov/ They have an API.