safedep / vet

Tool to achieve policy driven vetting of open source dependencies
Apache License 2.0
214 stars 17 forks source link

Avoid Duplicate Reporting of Lockfile Poisoning in Markdown Summary Reporter #231

Open abhisek opened 1 month ago

abhisek commented 1 month ago

This issue is manifested when there are a lot of packages from private repositories. Although we have a config option to add private repository URL to allow list, it makes sense to consolidate the finding by URL

Reference: https://github.com/safedep/vet-action/issues/37#issuecomment-2275005354