Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use GitLab's security API #2861

Closed
tsteenbe opened this issue Jul 15, 2020 · 3 comments
Closed

Use GitLab's security API #2861

tsteenbe opened this issue Jul 15, 2020 · 3 comments
Labels
advisor About the advisor tool new feature Issues that are considered to be new features

Comments

@tsteenbe
Copy link
Member

GitLab vulnerabilities database is Gemnasium DB which seem to be updated at least once a week and is available as a Git repository at https://gitlab.com/gitlab-org/security-products/gemnasium-db

This dataset is made available under GitLab Security Alert Database Terms

We would need to talk to GitHub as the above license states:

(f) Attempt to access or search the Security Alert Database or Content or download Content from the Security Alert Database through the use of any engine, software, tool, agent, device or mechanism (including spiders, robots, crawlers, data mining tools or the like) other than the software and/or search agents provided by GitLab or other generally available third-party web browsers;

Maybe we can get GitLab to provide REST APIs so GitLab Ultimate/Gold customers can user ORT to query gemnasium-db

@tsteenbe tsteenbe added the advisor About the advisor tool label Jul 15, 2020
@sschuberth sschuberth added the new feature Issues that are considered to be new features label Nov 4, 2020
@tsteenbe tsteenbe changed the title Use GitLab's security db? Use GitLab's security API Feb 25, 2021
@tsteenbe
Copy link
Member Author

GitLab is building API for gemnasium-db advisories see https://gitlab.com/gitlab-org/gitlab/-/issues/262400

@tsteenbe
Copy link
Member Author

GitLab just open-sourced a time-delayed clone of their security vulnerability data feed https://gitlab.com/gitlab-org/advisories-community (see also related https://gitlab.com/gitlab-org/gitlab/-/issues/326795)

@sschuberth
Copy link
Member

Even if not present at https://github.com/nexB/vulnerablecode/blob/main/SOURCES.rst, VulnerableCode seem to have support for this, so I believe we're fine closing this in favor of using our VulnerableCode integration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisor About the advisor tool new feature Issues that are considered to be new features
Projects
None yet
Development

No branches or pull requests

2 participants