Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / safedep/vet issues and pull requests

#138 - chore(deps-dev): bump @docusaurus/module-type-aliases from 2.4.0 to 2.4.3 in /docs

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies, javascript

#137 - chore(deps): bump prism-react-renderer from 1.3.5 to 2.1.0 in /docs

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies, javascript

#136 - chore(deps): bump @docusaurus/core from 2.4.0 to 2.4.3 in /docs

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies, javascript

#135 - feat: Add Support for RubyGems Ecosystem

Pull Request - State: closed - Opened by abhisek 11 months ago - 2 comments

#134 - chore(deps): bump github.com/gofri/go-github-ratelimit from 1.0.4 to 1.0.5

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies, go

#133 - chore(deps): bump github.com/google/osv-scanner from 1.4.1 to 1.4.2

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies, go

#132 - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.4.8 to 6.4.9

Pull Request - State: closed - Opened by dependabot[bot] 11 months ago - 2 comments
Labels: dependencies, go

#131 - chore(deps): bump postcss from 8.4.21 to 8.4.31 in /docs

Pull Request - State: open - Opened by dependabot[bot] 12 months ago - 1 comment
Labels: dependencies, javascript

#130 - chore(deps): bump urllib3 from 1.26.9 to 1.26.18 in /pkg/readers/fixtures/multi-with-invalid

Pull Request - State: closed - Opened by dependabot[bot] 12 months ago - 2 comments
Labels: dependencies, python

#129 - chore(deps): bump @babel/traverse from 7.21.3 to 7.23.2 in /docs

Pull Request - State: open - Opened by dependabot[bot] 12 months ago - 1 comment
Labels: dependencies, javascript

#128 - chore: Dependency Upgrade

Pull Request - State: closed - Opened by abhisek 12 months ago - 2 comments

#127 - chore(deps): bump github.com/deepmap/oapi-codegen from 1.13.3 to 1.16.2

Pull Request - State: closed - Opened by dependabot[bot] 12 months ago - 2 comments
Labels: dependencies, go

#126 - Refactor: Exceptions Management at Per Scan

Issue - State: open - Opened by abhisek 12 months ago
Labels: enhancement

#125 - Migrate to Using buf For Protocol Buffers Spec Management

Issue - State: open - Opened by abhisek 12 months ago
Labels: enhancement, refactor

#124 - Multiple Fixes and Enhancements

Pull Request - State: closed - Opened by abhisek 12 months ago - 1 comment

#123 - Fixed Issue with NPM sbom, fixed issues with cyclonedx parser, and refactored code

Pull Request - State: closed - Opened by jchauhan about 1 year ago - 1 comment

#122 - feat: Add Support for Github Connect for Private Repository Scanning

Pull Request - State: closed - Opened by abhisek about 1 year ago - 2 comments

#120 - FEAT - Added support to parse and scan SBOM in Spdx format

Pull Request - State: closed - Opened by jchauhan about 1 year ago - 1 comment

#119 - Fix: Vet Crash on one of the SBOM generate from Github #118

Pull Request - State: closed - Opened by jchauhan about 1 year ago - 1 comment

#118 - Vet Crash on one of the SBOM generate from Github

Issue - State: closed - Opened by jchauhan about 1 year ago

#117 - Ability to run vet on SBOM generated by github and give a single policy violation report

Issue - State: open - Opened by jchauhan about 1 year ago
Labels: enhancement

#116 - fix: enable cgo support as required by tree sitter

Pull Request - State: closed - Opened by abhisek about 1 year ago - 1 comment

#114 - Support Scanning Dependency Changes in Pull Request

Issue - State: closed - Opened by abhisek about 1 year ago - 1 comment
Labels: enhancement

#113 - Added ability to parse setup.py (Pypi) file and scan its dependencies

Pull Request - State: closed - Opened by jchauhan about 1 year ago - 1 comment

#112 - feat: CycloneDX SBOM Scanning Introduced by #111

Pull Request - State: closed - Opened by abhisek about 1 year ago - 1 comment

#111 - Jc

Pull Request - State: closed - Opened by jchauhan about 1 year ago - 2 comments

#110 - chore: Dependency upgrade as per dependabot suggestion

Pull Request - State: closed - Opened by abhisek about 1 year ago - 1 comment

#109 - feat: Cloud Report Sync : WIP

Pull Request - State: closed - Opened by abhisek about 1 year ago - 1 comment

#108 - Generate Report as SBOM

Issue - State: open - Opened by abhisek about 1 year ago
Labels: enhancement, sbom

#107 - Improve Remediation Advice

Issue - State: open - Opened by abhisek about 1 year ago
Labels: product, ux

#106 - Bump github.com/google/cel-go from 0.16.0 to 0.17.1

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies, go

#105 - Bump github.com/google/osv-scanner from 1.3.4 to 1.3.6

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies, go

#104 - Bump semver from 5.7.1 to 5.7.2 in /docs

Pull Request - State: open - Opened by dependabot[bot] about 1 year ago - 1 comment
Labels: dependencies, javascript

#103 - Bump golang.org/x/term from 0.8.0 to 0.10.0

Pull Request - State: closed - Opened by dependabot[bot] about 1 year ago - 2 comments
Labels: dependencies, go

#102 - Bump prism-react-renderer from 1.3.5 to 2.0.6 in /docs

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, javascript

#101 - Bump github.com/google/osv-scanner from 1.3.4 to 1.3.5

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#100 - Bump google.golang.org/protobuf from 1.30.0 to 1.31.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 3 comments
Labels: dependencies, go

#99 - Bump golang.org/x/term from 0.8.0 to 0.9.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#98 - chore: Update go dependencies

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment

#97 - Bump prism-react-renderer from 1.3.5 to 2.0.5 in /docs

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, javascript

#96 - Bump github.com/deepmap/oapi-codegen from 1.12.4 to 1.13.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 3 comments
Labels: dependencies, go

#95 - Bump github.com/google/osv-scanner from 1.3.2 to 1.3.4

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#94 - Support Vulnerability Reachability Analysis to Reduce False Positive

Issue - State: open - Opened by abhisek over 1 year ago
Labels: enhancement, research

#93 - Bump github.com/stretchr/testify from 1.8.2 to 1.8.4

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#92 - Bump github.com/sirupsen/logrus from 1.9.0 to 1.9.3

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#91 - Bump github.com/google/cel-go from 0.15.1 to 0.16.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#90 - Bump @docusaurus/module-type-aliases from 2.4.0 to 2.4.1 in /docs

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, javascript

#89 - Incorrect Update Recommendation

Issue - State: closed - Opened by anantshri over 1 year ago - 1 comment
Labels: bug

#88 - Bump github.com/google/cel-go from 0.15.1 to 0.15.3

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#87 - Bump @docusaurus/plugin-google-gtag from 2.4.0 to 2.4.1 in /docs

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, javascript

#86 - Bump github.com/stretchr/testify from 1.8.2 to 1.8.3

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#85 - Bump github.com/google/cel-go from 0.15.1 to 0.15.2

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#84 - Bump @docusaurus/core from 2.4.0 to 2.4.1 in /docs

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, javascript

#83 - Bump github.com/sirupsen/logrus from 1.9.0 to 1.9.2

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#82 - Bump github.com/google/osv-scanner from 1.3.2 to 1.3.3

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#81 - Bump prism-react-renderer from 1.3.5 to 2.0.4 in /docs

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, javascript

#80 - [npm] Recommended action is for tertiary dependencies which cant be touched.

Issue - State: open - Opened by anantshri over 1 year ago - 2 comments
Labels: enhancement

#79 - Bump github.com/google/cel-go from 0.14.0 to 0.15.1

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 1 comment
Labels: dependencies, go

#78 - Bump golang.org/x/term from 0.7.0 to 0.8.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 1 comment
Labels: dependencies, go

#77 - Bump github.com/google/osv-scanner from 1.3.1 to 1.3.2

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 1 comment
Labels: dependencies, go

#76 - Add Support for Community Endpoint for Insights API

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment
Labels: enhancement

#75 - Support SBOM as an Input Format for vet

Issue - State: closed - Opened by abhisek over 1 year ago - 1 comment
Labels: enhancement

#74 - Bump @mdx-js/react from 1.6.22 to 2.3.0 in /docs

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, javascript

#73 - Explore Fury.io for Publishing OS Native Packages

Issue - State: open - Opened by abhisek over 1 year ago - 1 comment
Labels: devops

#72 - Fix bug in pywheel spec parser

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment

#71 - Sync Develop to Main

Pull Request - State: closed - Opened by abhisek over 1 year ago - 2 comments

#70 - Sync Develop to Main

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment

#69 - Adds CSV Reporter for Output :#6

Pull Request - State: closed - Opened by shivamsk over 1 year ago - 1 comment

#68 - Fix Bug in Python Wheel File Package Spec Parsing

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment

#67 - Analyse Integration of OSV and Deps.dev API to Decouple vet from SafeDep Backend

Issue - State: closed - Opened by abhisek over 1 year ago - 1 comment
Labels: research

#66 - Added homebrew installation instructions

Pull Request - State: closed - Opened by madhuakula over 1 year ago - 1 comment
Labels: documentation, enhancement

#65 - Sync Develop to Main

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment

#64 - Config Spec Driven Scan Execution

Issue - State: open - Opened by abhisek over 1 year ago
Labels: enhancement

#62 - Bump github.com/stretchr/testify from 1.8.1 to 1.8.2

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#61 - Bump github.com/golang/protobuf from 1.5.2 to 1.5.3

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#60 - Bump github.com/google/cel-go from 0.13.0 to 0.14.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#59 - Added feature for showing Ecosystem name in the table along with othe…

Pull Request - State: closed - Opened by tarunsamanta2k20 over 1 year ago - 6 comments

#58 - Added linter support on ci

Pull Request - State: closed - Opened by tarunsamanta2k20 over 1 year ago - 3 comments

#57 - Support PURL Data Source for Single Package Scanning

Issue - State: closed - Opened by abhisek over 1 year ago - 1 comment
Labels: enhancement, good first issue

#56 - Use vet to Implement Safe Consumption of OSS Components for vet

Issue - State: open - Opened by abhisek over 1 year ago - 2 comments
Labels: good first issue, help wanted

#55 - Fix Linter Issues and Enable `golint` Guard Rail

Issue - State: closed - Opened by abhisek over 1 year ago - 2 comments
Labels: good first issue

#54 - Show Ecosystem Name in Summary Report

Issue - State: closed - Opened by abhisek over 1 year ago - 2 comments
Labels: enhancement, good first issue

#53 - Refactor Package Readers into a Standard Interface

Pull Request - State: closed - Opened by abhisek over 1 year ago - 2 comments
Labels: enhancement

#52 - Dependabot updates for go pkg

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment

#51 - Bump github.com/google/osv-scanner from 1.2.0 to 1.3.1

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#50 - Bump google.golang.org/protobuf from 1.28.1 to 1.30.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#49 - Bump golang.org/x/term from 0.5.0 to 0.7.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#48 - Bump github.com/jedib0t/go-pretty/v6 from 6.4.4 to 6.4.6

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#47 - Bump github.com/spf13/cobra from 1.6.1 to 1.7.0

Pull Request - State: closed - Opened by dependabot[bot] over 1 year ago - 2 comments
Labels: dependencies, go

#46 - Create .github/dependabot.yml

Pull Request - State: closed - Opened by abhisek over 1 year ago - 1 comment

#45 - adding homebrew-vet tap

Pull Request - State: closed - Opened by madhuakula over 1 year ago - 1 comment
Labels: enhancement

#44 - Fix-27 Duplicate findings in report summery

Pull Request - State: closed - Opened by c0d3G33k over 1 year ago

#43 - Explore (Open) VEX Statement Generation

Issue - State: open - Opened by abhisek over 1 year ago
Labels: enhancement, research

#41 - Sync Develop to Main

Pull Request - State: closed - Opened by abhisek over 1 year ago - 2 comments

#40 - Configurable ignoreable directory

Issue - State: closed - Opened by Hritik14 over 1 year ago - 1 comment
Labels: enhancement

#39 - Evaluate ko for Building vet Container Image

Issue - State: open - Opened by abhisek over 1 year ago - 1 comment
Labels: good first issue

#38 - Implement E2E Behavior Testing

Issue - State: open - Opened by abhisek over 1 year ago
Labels: enhancement, good first issue, help wanted

#37 - added social links

Pull Request - State: closed - Opened by madhuakula over 1 year ago

#36 - Fixed docs url

Pull Request - State: closed - Opened by madhuakula over 1 year ago - 1 comment