mitre / hipcheck

Automatically assess and score software repositories for supply chain risk.
https://mitre.github.io/hipcheck/
Apache License 2.0
62 stars 3 forks source link

feat(CLI): CLI can infer target type from target pURL #205

Closed mchernicoff closed 1 month ago

mchernicoff commented 1 month ago

Resolves issue #184 .

hc check will now attempt to resolve the target type from a given target pURL. Currently we support GitHub, Maven, NPM, and PyPi pURL's. If a target type can be resolved, Hipcheck will extract the information it needs to run from the pURL.

If the user provides a target type to hc check with the -t flag, Hipcheck will error if the inferred type (whether inferred from a pURL, GitHub URL, or .spdx file extension) does not match the provided type.

alilleybrinker commented 1 month ago

Ugh, it looks like a spam account called "GO-NFT-GO" left a "review" on the project with a spam message of "ok" (likely to farm apparent contribution stats for their account) on this PR. I literally can't find / open the conversation, but GitHub swear it exists and is blocking merging over it.

alilleybrinker commented 1 month ago

Ugh, it looks like a spam account called "GO-NFT-GO" left a "review" on the project with a spam message of "ok" (likely to farm apparent contribution stats for their account) on this PR. I literally can't find / open the conversation, but GitHub swear it exists and is blocking merging over it.

It looks like the offending "review" is on an orphan commit from before the force-push.

mchernicoff commented 1 month ago

Ugh, it looks like a spam account called "GO-NFT-GO" left a "review" on the project with a spam message of "ok" (likely to farm apparent contribution stats for their account) on this PR. I literally can't find / open the conversation, but GitHub swear it exists and is blocking merging over it.

It looks like the offending "review" is on an orphan commit from before the force-push.

https://stackoverflow.com/questions/71946575/after-rebase-and-force-push-unresolved-conversations-remain-outdated-and-block