snyk / parlay

Enrich SBOMs with data from third party services
Apache License 2.0
121 stars 19 forks source link

Add support for enrichment using deps.dev #1

Open garethr opened 1 year ago

garethr commented 1 year ago

the deps.dev API contains interesting package and repository information for a small number of ecosystems, including Scorecard data. I have an open question that likely wants clarifying around the license for the data however.

garethr commented 1 year ago

Some work-in-progress in https://github.com/snyk/parlay/tree/deps