Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / eBay/sbom-scorecard issues and pull requests

#45 - Consider contributing to OpenSSF

Issue - State: open - Opened by lucasgonze about 1 year ago

#43 - Update authoritative source

Pull Request - State: open - Opened by justinabrahms over 1 year ago

#40 - upgrade slsa-verifier: 2.0.1 -> 2.1.0

Pull Request - State: closed - Opened by developer-guy over 1 year ago

#39 - feature: enable verification for provenance

Pull Request - State: closed - Opened by developer-guy over 1 year ago

#38 - feat(scorecard):Display result in Table format

Pull Request - State: closed - Opened by dineshr93 over 1 year ago - 1 comment

#37 - JSON output does not produce # of total packages

Issue - State: closed - Opened by emkaminsk over 1 year ago - 1 comment

#36 - Consider Alternative Identifier Logic Related to purl and CPEs

Issue - State: closed - Opened by jspeed-meyers over 1 year ago - 2 comments

#35 - Add licenseRef to test case

Pull Request - State: closed - Opened by jspeed-meyers over 1 year ago - 2 comments

#34 - Evaluate & Adhere (or have good reasons why not) to NTIA minimal elements

Issue - State: open - Opened by justinabrahms over 1 year ago - 3 comments
Labels: help wanted

#33 - Update spdx library

Pull Request - State: closed - Opened by justinabrahms over 1 year ago

#32 - fix nil pointer reference bug & NaN handling on invalid json input

Pull Request - State: closed - Opened by frenchi over 1 year ago - 2 comments

#31 - add publish image workflow

Pull Request - State: closed - Opened by developer-guy over 1 year ago - 1 comment

#30 - Add usage image

Pull Request - State: closed - Opened by justinabrahms over 1 year ago

#29 - Fix integer division by integer bug

Pull Request - State: closed - Opened by jspeed-meyers over 1 year ago

#28 - BUG: Dividing Integers by Integers Leads to Incorrect Score Calculation

Issue - State: closed - Opened by jspeed-meyers over 1 year ago - 1 comment

#27 - spdx: follow LicenseRefs

Issue - State: closed - Opened by justinabrahms over 1 year ago - 2 comments

#26 - spdx: use both licenseConcluded & licenseDeclared

Issue - State: closed - Opened by justinabrahms over 1 year ago

#25 - tag-value documents not parsing properly

Issue - State: closed - Opened by justinabrahms over 1 year ago - 6 comments

#24 - Fix Package Version Logic for CDX Parsing

Pull Request - State: closed - Opened by jspeed-meyers over 1 year ago

#23 - Inline tutorial into the README

Pull Request - State: closed - Opened by justinabrahms over 1 year ago

#22 - SPDX questions/bugs

Issue - State: closed - Opened by rnjudge over 1 year ago - 5 comments

#21 - Tutorial is wrong about installation.

Issue - State: closed - Opened by justinabrahms over 1 year ago

#20 - Minor tutorial updates

Pull Request - State: closed - Opened by jspeed-meyers over 1 year ago - 4 comments

#19 - Add support for Tag Value and YAML SPDX files

Issue - State: closed - Opened by anthonyharrison over 1 year ago

#18 - Add tutorial.md and reference to tutorial in README.md

Pull Request - State: closed - Opened by jspeed-meyers over 1 year ago - 1 comment

#17 - Fix check for component hash existence

Pull Request - State: closed - Opened by jspeed-meyers almost 2 years ago

#16 - Code assumes json format for CycloneDX SBOMs

Issue - State: closed - Opened by cyberbliss almost 2 years ago - 2 comments

#15 - BUG: Trivy CycloneDX scan does not work

Issue - State: closed - Opened by AnaisUrlichs almost 2 years ago - 4 comments

#14 - tutorial missing

Issue - State: closed - Opened by AnaisUrlichs almost 2 years ago - 7 comments

#13 - Add SPDX 2.3 support

Pull Request - State: closed - Opened by puerco almost 2 years ago - 2 comments

#12 - Handle panic when handling non 2.2 SPDX docs

Pull Request - State: closed - Opened by puerco almost 2 years ago

#11 - [Potential Bug] cyclonedx logic on package versions uses package digest

Issue - State: closed - Opened by jspeed-meyers almost 2 years ago - 1 comment

#10 - Add pkg version for spdx

Pull Request - State: closed - Opened by jspeed-meyers almost 2 years ago

#9 - Add SPDX package version logic

Issue - State: closed - Opened by jspeed-meyers almost 2 years ago

#8 - [Feature Request] Auto-Detect SBOM Format

Issue - State: closed - Opened by jspeed-meyers almost 2 years ago - 1 comment

#7 - Support json output

Issue - State: closed - Opened by justinabrahms almost 2 years ago

#6 - Add CLI support

Issue - State: closed - Opened by pxp928 almost 2 years ago

#5 - added cli and re-organized packages

Pull Request - State: closed - Opened by pxp928 almost 2 years ago

#4 - BOM Maturity Model

Issue - State: closed - Opened by stevespringett almost 2 years ago - 3 comments

#3 - Support for CycloneDX

Issue - State: closed - Opened by justinabrahms almost 2 years ago - 1 comment

#2 - Support for Syft

Issue - State: open - Opened by justinabrahms almost 2 years ago

#1 - updated spdx to include files

Pull Request - State: closed - Opened by pxp928 almost 2 years ago