Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss
Looking at some non-cocoapods vcs_url values (generated from info() in fetchcode/package.py) -- which often come from the git_url value in https://api.github.com/repos/{repo_owner}/{repo_name} for those PURLs with a GH repo -- I see some that look like this
for pkg:github/avahi/avahi@0.8 -- "vcs_url": "git://github.com/avahi/avahi.git" (in https://api.github.com/repos/avahi/avahi, we see "git_url": "git://github.com/avahi/avahi.git")
or
for pkg:npm/canonical-path@1.0.0 -- "vcs_url": "git+https://github.com/petebacondarwin/node-canonical-path.git" (in https://api.github.com/repos/petebacondarwin/node-canonical-path it's slightly different from the vcs_url -- "git_url": "git://github.com/petebacondarwin/node-canonical-path.git")
and others like this
for pkg:npm/canonical-path@0.0.2 -- "vcs_url": "https://github.com/petebacondarwin/node-canonical-path" (as noted just above for @1.0.0, the git_url starts with git: and ends with .git.
Looking at some non-cocoapods
vcs_url
values (generated frominfo()
infetchcode/package.py
) -- which often come from thegit_url
value inhttps://api.github.com/repos/{repo_owner}/{repo_name}
for those PURLs with a GH repo -- I see some that look like thispkg:github/avahi/avahi@0.8
--"vcs_url": "git://github.com/avahi/avahi.git"
(in https://api.github.com/repos/avahi/avahi, we see"git_url": "git://github.com/avahi/avahi.git"
)or
pkg:npm/canonical-path@1.0.0
--"vcs_url": "git+https://github.com/petebacondarwin/node-canonical-path.git"
(in https://api.github.com/repos/petebacondarwin/node-canonical-path it's slightly different from thevcs_url
--"git_url": "git://github.com/petebacondarwin/node-canonical-path.git"
)and others like this
pkg:npm/canonical-path@0.0.2
--"vcs_url": "https://github.com/petebacondarwin/node-canonical-path"
(as noted just above for @1.0.0, thegit_url
starts withgit:
and ends with.git
.