Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: improved scannning a python site-packages directory #4330

Open
terriko opened this issue Aug 9, 2024 · 0 comments
Open

feat: improved scannning a python site-packages directory #4330

terriko opened this issue Aug 9, 2024 · 0 comments
Labels
hackathon Issues for folk participating in the Open Ecosystems hackathon
Milestone

Comments

@terriko
Copy link
Contributor

terriko commented Aug 9, 2024

It came up in a question I got that someone is scanning their site-packages directory as a way to see if they have vulnerabilities.

While we do read the METADATA file I'm not sure it works quite as well as one might expect. For example, I'm not sure if we do some the things we added later with requirements.txt scanning to use pip and figure out indirect dependencies.

Would love it if someone had some time to review that code and see what (if anything) we could do to better support scanning a whole site-packages directory. Maybe it's fine? but I feel like it could almost certainly be better.

@terriko terriko added the hackathon Issues for folk participating in the Open Ecosystems hackathon label Aug 9, 2024
@terriko terriko added this to the future milestone Aug 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
hackathon Issues for folk participating in the Open Ecosystems hackathon
Projects
None yet
Development

No branches or pull requests

1 participant