Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / guacsec/guac issues and pull requests

#2151 - fix error handling on certifier

Pull Request - State: open - Opened by pxp928 6 days ago
Labels: size/M

#2150 - [bug] CD certifier never completes due to errors encountered

Issue - State: open - Opened by pxp928 6 days ago
Labels: bug

#2149 - add logs to determine when certifier starts and ends

Pull Request - State: closed - Opened by pxp928 7 days ago
Labels: size/S

#2148 - bump github.com/99designs/gqlgen from 0.17.49 to 0.17.54

Pull Request - State: closed - Opened by dependabot[bot] 8 days ago - 1 comment
Labels: dependencies, go, size/S

#2147 - bump github.com/nats-io/nats-server/v2 from 2.10.18 to 2.10.20

Pull Request - State: closed - Opened by dependabot[bot] 8 days ago - 1 comment
Labels: dependencies, size/XS, go

#2146 - bump github.com/aws/aws-sdk-go-v2 from 1.30.5 to 1.31.0

Pull Request - State: closed - Opened by dependabot[bot] 8 days ago
Labels: dependencies, go, size/S

#2145 - bump github.com/google/osv-scanner from 1.8.4 to 1.8.5

Pull Request - State: closed - Opened by dependabot[bot] 8 days ago - 1 comment
Labels: dependencies, go, size/M

#2144 - Bump google.golang.org/api from 0.192.0 to 0.198.0

Pull Request - State: closed - Opened by dependabot[bot] 8 days ago - 1 comment
Labels: size/L, dependencies, go

#2143 - Bump github/codeql-action from 3.26.7 to 3.26.8

Pull Request - State: closed - Opened by dependabot[bot] 8 days ago - 1 comment
Labels: dependencies, github_actions, size/XS

#2142 - [feature] Add ClearlyDefined to e2e test

Issue - State: open - Opened by pxp928 8 days ago
Labels: enhancement, good first issue, help wanted

#2141 - feat: add isDeployed POC

Pull Request - State: closed - Opened by akashsinghal 11 days ago - 2 comments
Labels: size/XL

#2140 - fix bugs that causes panic on query vuln on sbom uri search

Pull Request - State: closed - Opened by pxp928 11 days ago
Labels: size/S

#2139 - [ENT] drop discovered_license from required index on certifyLegal

Pull Request - State: closed - Opened by pxp928 12 days ago
Labels: size/S

#2137 - [CDX] create isoccur for top level package when artifact is found

Pull Request - State: closed - Opened by pxp928 13 days ago
Labels: size/S

#2136 - Fix guacEmpty being added into the ENT DB causing errors

Pull Request - State: closed - Opened by pxp928 13 days ago
Labels: size/L

#2135 - [bug] ent: constraint failed: insert nodes to table \"source_names\"

Issue - State: closed - Opened by pxp928 13 days ago
Labels: bug

#2134 - Update CD certifier to ignore LicenseRef licenses

Pull Request - State: closed - Opened by jeffmendoza 14 days ago
Labels: size/S

#2133 - [bug] ClearlyDefined certifier failing on certain packages

Issue - State: open - Opened by jeffmendoza 14 days ago
Labels: bug

#2132 - Bump actions/create-github-app-token from 1.10.4 to 1.11.0

Pull Request - State: closed - Opened by dependabot[bot] 15 days ago
Labels: dependencies, github_actions, size/XS

#2131 - Bump github/codeql-action from 3.26.6 to 3.26.7

Pull Request - State: closed - Opened by dependabot[bot] 15 days ago
Labels: dependencies, github_actions, size/XS

#2130 - Also add the ClearlyDefined certifier to the postgres compose file

Pull Request - State: closed - Opened by funnelfiasco 18 days ago
Labels: size/S

#2129 - Add the ClearlyDefined certifier to the demo compose file

Pull Request - State: closed - Opened by funnelfiasco 20 days ago
Labels: size/S

#2128 - [feature] Add the ClearlyDefined certifier to the demo compose file

Issue - State: closed - Opened by funnelfiasco 20 days ago
Labels: enhancement

#2127 - [bug] Ingesting SBOMs results in license error

Issue - State: open - Opened by nathannaveen 20 days ago - 6 comments
Labels: bug

#2126 - CDX parser captures version as an artifact for images

Pull Request - State: closed - Opened by nathannaveen 20 days ago
Labels: size/L

#2125 - [Fix] GRPC rate limit and add exponential backoff for CD

Pull Request - State: closed - Opened by pxp928 20 days ago
Labels: size/XL

#2124 - [bug] deps.dev hangs with new rate limit logic

Issue - State: closed - Opened by pxp928 20 days ago
Labels: bug

#2122 - retry on network error for certifiers

Pull Request - State: closed - Opened by pxp928 21 days ago - 1 comment
Labels: size/M

#2121 - Bump github.com/aws/aws-sdk-go-v2 from 1.30.4 to 1.30.5

Pull Request - State: closed - Opened by dependabot[bot] 22 days ago
Labels: dependencies, size/XS, go

#2120 - Bump gocloud.dev/pubsub/rabbitpubsub from 0.38.0 to 0.39.0

Pull Request - State: closed - Opened by dependabot[bot] 22 days ago
Labels: size/L, dependencies, go

#2119 - Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.59.0 to 1.61.2

Pull Request - State: closed - Opened by dependabot[bot] 22 days ago
Labels: dependencies, go, size/M

#2118 - Bump gocloud.dev from 0.38.0 to 0.39.0

Pull Request - State: closed - Opened by dependabot[bot] 22 days ago
Labels: size/L, dependencies, go

#2117 - Bump google.golang.org/grpc from 1.66.0 to 1.66.1

Pull Request - State: closed - Opened by dependabot[bot] 22 days ago
Labels: dependencies, size/XS, go

#2116 - Bump actions/create-github-app-token from 1.10.3 to 1.10.4

Pull Request - State: closed - Opened by dependabot[bot] 22 days ago
Labels: dependencies, github_actions, size/XS

#2115 - add connection timeout for ENT

Pull Request - State: closed - Opened by pxp928 22 days ago
Labels: size/M

#2114 - change atlas migration to take into account ent auto migration index names

Pull Request - State: closed - Opened by pxp928 22 days ago
Labels: size/XS

#2113 - [feature] Clean up repeated loop and type checking

Issue - State: open - Opened by nathannaveen 22 days ago
Labels: enhancement

#2112 - Bump getkin/kin-openapi from `v0.123.0` to `v0.127.0`

Pull Request - State: closed - Opened by nathannaveen 25 days ago
Labels: size/M

#2111 - Include documentRef in hasSBOM client operations

Pull Request - State: closed - Opened by nathannaveen 26 days ago
Labels: size/M

#2110 - Bump getkin/kin-openapi from 0.123.0 to 0.127.0

Pull Request - State: closed - Opened by nathannaveen 26 days ago
Labels: size/M

#2109 - [feature] ENT set db.SetConnMaxLifetime()

Issue - State: closed - Opened by pxp928 27 days ago
Labels: enhancement, good first issue, help wanted

#2108 - Bumping cdevents/sdk-go from 0.3.2 to 0.4.1

Pull Request - State: closed - Opened by nathannaveen 27 days ago
Labels: size/M

#2107 - Bump docker/login-action from 2 to 3

Pull Request - State: closed - Opened by dependabot[bot] 29 days ago
Labels: dependencies, github_actions, size/XS

#2106 - Bump actions/setup-python from 5.1.1 to 5.2.0

Pull Request - State: closed - Opened by dependabot[bot] 29 days ago
Labels: dependencies, github_actions, size/XS

#2105 - Bump github/codeql-action from 3.26.5 to 3.26.6

Pull Request - State: closed - Opened by dependabot[bot] 29 days ago
Labels: dependencies, github_actions, size/XS

#2104 - Bump github.com/fsouza/fake-gcs-server from 1.49.2 to 1.49.3

Pull Request - State: closed - Opened by dependabot[bot] 29 days ago
Labels: size/L, dependencies, go

#2103 - Bump google.golang.org/grpc from 1.65.0 to 1.66.0

Pull Request - State: closed - Opened by dependabot[bot] 29 days ago
Labels: dependencies, size/XS, go

#2102 - Bump github.com/aws/aws-sdk-go-v2/config from 1.27.28 to 1.27.31

Pull Request - State: closed - Opened by dependabot[bot] 29 days ago
Labels: dependencies, go, size/S

#2101 - Fix SPDX SBOM ingestion with multiple purls in externalRefs array

Pull Request - State: closed - Opened by mrizzi 29 days ago
Labels: size/L

#2100 - [ingestion/data-quality issue] SPDX SBOM missing data a package has multiple purls

Issue - State: closed - Opened by mrizzi 29 days ago
Labels: bug, data-quality, data-sources

#2099 - [feature] Add documentRef to HasSbom client operations

Issue - State: closed - Opened by jeffmendoza about 1 month ago
Labels: enhancement, good first issue, help wanted

#2098 - [feature] CDX parsing to capture version as an artifact for images

Issue - State: closed - Opened by pxp928 about 1 month ago
Labels: enhancement, good first issue, help wanted

#2097 - Bump github/codeql-action from 3.26.3 to 3.26.5

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, github_actions, size/XS

#2096 - Bump docker/setup-buildx-action from 2 to 3

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, github_actions, size/XS

#2095 - Bump docker/build-push-action from 5 to 6

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, github_actions, size/XS

#2094 - Bump actions/checkout from 3 to 4

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, github_actions, size/XS

#2093 - Bump anchore/sbom-action from 0.17.1 to 0.17.2

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, github_actions, size/XS

#2092 - Bump entgo.io/contrib from 0.5.0 to 0.6.0

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, go, size/S

#2091 - Bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.34.3 to 1.34.5

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, size/XS, go

#2090 - Bump github.com/google/osv-scanner from 1.8.2 to 1.8.4

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, go, size/M

#2089 - Search REST via Purl

Pull Request - State: open - Opened by nathannaveen about 1 month ago - 2 comments
Labels: size/XXL

#2088 - Add batch querying for clearly defined to reduce ingestion time

Pull Request - State: closed - Opened by pxp928 about 1 month ago
Labels: size/XXL

#2087 - atlas migration update to build/publish only on tag release

Pull Request - State: closed - Opened by pxp928 about 1 month ago
Labels: size/XS

#2086 - Atlas migration image

Pull Request - State: closed - Opened by pxp928 about 1 month ago
Labels: size/M

#2085 - Bump github/codeql-action from 3.26.0 to 3.26.3

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, github_actions, size/XS

#2084 - Bump anchore/sbom-action from 0.17.0 to 0.17.1

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, github_actions, size/XS

#2083 - Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.58.2 to 1.59.0

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago
Labels: dependencies, go, size/M

#2082 - Bump github.com/aws/aws-sdk-go-v2 from 1.30.3 to 1.30.4

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago - 2 comments
Labels: dependencies, go, size/S

#2081 - Bump github.com/aws/aws-sdk-go-v2/config from 1.27.23 to 1.27.28

Pull Request - State: closed - Opened by dependabot[bot] about 1 month ago - 1 comment
Labels: dependencies, go, size/M

#2080 - remove daysSinceLastScan as it is redundant with certifier interval

Pull Request - State: closed - Opened by pxp928 about 2 months ago - 2 comments
Labels: size/XL

#2079 - [fix] cdx parser empty purl identifier and deduplication

Pull Request - State: closed - Opened by pxp928 about 2 months ago
Labels: size/M

#2078 - [ingestion/bug] identifier purl is empty string

Issue - State: closed - Opened by pxp928 about 2 months ago
Labels: bug, data-quality, data-sources

#2077 - [ingestion/clearlydefined] clearlydefined fails to run when the osv certifier has already run

Issue - State: closed - Opened by pxp928 about 2 months ago - 3 comments
Labels: bug, data-quality, data-sources

#2076 - expose hasSBOM and hasSLSA IDs

Pull Request - State: closed - Opened by pxp928 about 2 months ago
Labels: size/S

#2075 - Bump sigstore/cosign-installer from 3.5.0 to 3.6.0

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago
Labels: dependencies, github_actions, size/XS

#2074 - Bump github/codeql-action from 3.25.15 to 3.26.0

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago
Labels: dependencies, github_actions, size/XS

#2073 - Bump github.com/sigstore/sigstore from 1.8.7 to 1.8.8

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago - 2 comments
Labels: dependencies, go, size/S

#2072 - Bump github.com/cdevents/sdk-go from 0.3.2 to 0.4.1

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago - 1 comment
Labels: dependencies, go, size/S

#2071 - Bump cloud.google.com/go/storage from 1.42.0 to 1.43.0

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago
Labels: dependencies, go, size/M

#2070 - Bump github.com/aws/aws-sdk-go from 1.55.0 to 1.55.5

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago
Labels: dependencies, size/XS, go

#2069 - Return hasSBOM and hasSLSA IDs from the assembler

Pull Request - State: closed - Opened by pxp928 about 2 months ago
Labels: size/L

#2069 - Return hasSBOM and hasSLSA IDs from the assembler

Pull Request - State: closed - Opened by pxp928 about 2 months ago
Labels: size/L

#2068 - Bump golangci/golangci-lint-action from 6.0.1 to 6.1.0

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago
Labels: dependencies, github_actions, size/XS

#2067 - Bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.31.4 to 1.34.3

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago - 1 comment
Labels: dependencies, size/XS, go

#2066 - Bump github.com/getkin/kin-openapi from 0.123.0 to 0.127.0

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago - 5 comments
Labels: dependencies, go, size/S

#2065 - Bump gocloud.dev/pubsub/rabbitpubsub from 0.37.0 to 0.38.0

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago
Labels: dependencies, go, size/M

#2064 - Find Latest SBOM for a Package or Artifact

Pull Request - State: closed - Opened by nathannaveen about 2 months ago - 2 comments
Labels: size/L

#2063 - Bump github.com/regclient/regclient from 0.7.0 to 0.7.1

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago - 1 comment
Labels: dependencies, size/XS, go

#2063 - Bump github.com/regclient/regclient from 0.7.0 to 0.7.1

Pull Request - State: closed - Opened by dependabot[bot] about 2 months ago - 1 comment
Labels: dependencies, size/XS, go

#2062 - ensure cdx parser does not error on v1.5 or below license parsing

Pull Request - State: closed - Opened by pxp928 about 2 months ago
Labels: size/L

#2060 - update dependency schema to make dependent_package_version_id required

Pull Request - State: closed - Opened by pxp928 2 months ago
Labels: size/XS

#2058 - [feature] Questions regarding adding REST Endpoints for Vulnerability and Legal info in an SBOM

Issue - State: open - Opened by nathannaveen 2 months ago - 8 comments
Labels: enhancement

#2053 - Rate limiting outgoing requests

Pull Request - State: closed - Opened by nathannaveen 2 months ago - 2 comments
Labels: size/XL

#2048 - [ingestion bug] Ingesting this specific CDX SBOM will cause a panic

Issue - State: closed - Opened by nchelluri 2 months ago - 7 comments
Labels: bug, data-quality, data-sources

#2040 - Bump github.com/99designs/gqlgen from 0.17.48 to 0.17.49

Pull Request - State: closed - Opened by dependabot[bot] 2 months ago - 3 comments
Labels: dependencies, size/XS, go

#2037 - [feature] Add support for endoflife.date

Issue - State: open - Opened by funnelfiasco 2 months ago - 1 comment
Labels: enhancement, good first issue, help wanted

#2033 - Implemented a Delete functionality for KeyValue

Pull Request - State: open - Opened by nathannaveen 3 months ago - 1 comment
Labels: size/L

#2011 - [feature] Rate limit outgoing http requests

Issue - State: closed - Opened by jeffmendoza 3 months ago - 1 comment
Labels: enhancement