ossf / disclosure-check

Apache License 2.0
3 stars 0 forks source link

Validate 50 projects manually #8

Open scovetta opened 1 year ago

scovetta commented 1 year ago

I'd like to have more confidence that we're generating accurate results. To do this, I'd like to manually verify 50 randomly sampled projects to ensure that we agree with the tool output -- meaning, that we think it'd be reasonable to go with the top option as the first choice.

If anyone would like to work on this, please just comment below with the package that you've checked and whether or not it was correct. If it wasn't correct, please open an issue so we can improve the tool.

scovetta commented 1 year ago
Package URL Status
pkg:github/ossf/alpha-omega Bug #14, fixed
scovetta commented 1 year ago
Ecosystem Name URL Correct Detection?
github ckeditor4 https://github.com/ckeditor/ckeditor4 Yes
rubygems rack https://rubygems.org/gems/rack Yes
npm babel-helper-regex https://www.npmjs.com/package/babel-helper-regex Yes
github pytest-mock https://github.com/pytest-dev/pytest-mock Yes
debian libtie-ixhash-perl https://packages.debian.org/search?keywords=libtie-ixhash-perl Yes
npm path-browserify Yes
github sqlx https://github.com/launchbadge/sqlx Yes
github abp https://github.com/abpframework/abp Yes
github SWFTools https://github.com/matthiaskramm/swftools Yes
github rails_event_store https://github.com/RailsEventStore/rails_event_store Yes
npm underscore Yes
github ros https://github.com/ros/ros Yes
npm node-forge Yes
npm faker Yes
npm mime-db Yes
github rubygems.org https://github.com/rubygems/rubygems.org Yes
github core-foundation-rs https://github.com/servo/core-foundation-rs
github auto https://github.com/google/auto Yes
github learnxinyminutes-docs https://github.com/adambard/learnxinyminutes-docs
debian libgnutls30 https://packages.debian.org/search?keywords=libgnutls30
github ecto https://github.com/elixir-ecto/ecto Yes
github pry https://github.com/pry/pry Yes
debian libsoup-gnome2.4-1 https://packages.debian.org/search?keywords=libsoup-gnome2.4-1 Yes
github Embed https://github.com/oscarotero/Embed Yes
debian libdatrie1 https://packages.debian.org/search?keywords=libdatrie1 Yes
go github.com/grpc-ecosystem/go-grpc-middleware
github crate https://github.com/crate/crate Yes
github twine https://github.com/pypa/twine
github routing https://github.com/symfony/routing Yes
maven commons-cli:commons-cli
github android https://github.com/nextcloud/android
github ansible https://github.com/ansible/ansible Yes
github rack-cors https://github.com/cyu/rack-cors Yes
github minimist http://github.com/substack/minimist
nuget system.valuetuple
nuget microsoft.netcore.targets.dnxcore
github cpputest https://github.com/cpputest/cpputest
npm cors Yes
github joblib https://github.com/joblib/joblib
github graphql-java https://github.com/graphql-java/graphql-java
github immer https://github.com/immerjs/immer
debian libglu1-mesa https://packages.debian.org/search?keywords=libglu1-mesa
github image https://github.com/containers/image Yes
github pyright https://github.com/microsoft/pyright
npm commondir Yes
debian libopencore-amrnb0 https://packages.debian.org/search?keywords=libopencore-amrnb0 Yes
github make https://github.com/mirror/make Yes
github validator https://github.com/symfony/validator
github auspice https://github.com/nextstrain/auspice
npm postcss-value-parser Yes
scovetta commented 1 year ago

Fix github/ros/ros via 9aad226f