Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

govulncheck mirror #1916

Open
pboguslawski opened this issue Feb 15, 2024 · 1 comment
Open

govulncheck mirror #1916

pboguslawski opened this issue Feb 15, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@pboguslawski
Copy link

Is your feature request related to a problem? Please describe.
Devs use local athens as proxy for module downloading/caching but cannot use it for module security audits.

Describe the solution you'd like
Add option to allow athens to periodically (configurable cron-like schedule) mirror and serve Go Vunerability Database (govulncheck allows to use custom db using -db parameter).

@matt0x6F matt0x6F added the enhancement New feature or request label Feb 19, 2024
@matt0x6F
Copy link
Contributor

I like the idea, but I think it falls outside of the definition of a Go Module Proxy like Athens. Go's own vulnerability database is separate from their proxy (but maybe is informed by it?). It's browseable primarily through the pkgsite. It does look like the spec for the server is documented though.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants