nexB / purldb

Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss
https://purldb.readthedocs.io/
29 stars 21 forks source link

PurlDB: Find the source package of a distro package so it can be scanned and indexed #408

Open pombredanne opened 2 months ago

pombredanne commented 2 months ago

We need to find, scan and index the source package of a distro package found in a container. Why? the binaries most often have sketchy origin and license data. Some specific issues for specific distros (more to add):