Open
Description
Should re-packagings of software artifacts from other ecosystems be supported for automatic inclusion in security advisories?
As a specific example, there exists the webjars project which packages javascript packages up and makes them available on Maven for inclusion of js dependencies in a java project. It might be useful to have these automatically included on new npm advisories for which a webjars artifact exists
Continues discussions from #607
Metadata
Metadata
Assignees
Labels
No labels