[VOTE] Create pypa/advisory-db

(Based on discussion at https://discuss.python.org/t/proposing-a-community-maintained-database-of-py... ) I propose the creation of a project in the PyPA organization: https://github.com/pypa/advisory-db which will be a community maintained database of PyPI package vulnerabilities. Please vote! +1 from me.

+1 -- Cooper Ry Lees [e] me@cooperlees.com [m] +1 (650) 798 7815 [w] http://cooperlees.com/ On Mon, May 24, 2021 at 9:27 AM Dustin Ingram <di@python.org> wrote:

I like this idea. The advisory repo looks like it's being kept up to date by https://github.com/osv-robot which as far as I can tell looks like a Google-run bot. Is the source for that bot available somewhere? Will a non-Googler be able to continue to maintain this repo if Google chooses to stop sponsoring the work? - e On 2021-05-24 09:27, Dustin Ingram wrote:

Great question, would you mind asking it at https://discuss.python.org/t/proposing-a-community-maintained-database-of-py... instead? If not, do you mind if I copy/paste it there for the benefit of folks not on this private mailing list? On Mon, May 24, 2021 at 6:08 PM Elana Hashman <ehashman@debian.org> wrote:

(I responded to Elana's questions here: https://discuss.python.org/t/proposing-a-community-maintained-database-of-py... ) On Mon, May 24, 2021 at 6:31 PM Dustin Ingram <di@python.org> wrote:

On Mon, May 24, 2021 at 6:28 PM Dustin Ingram <di@python.org> wrote:
+1 -- Warm regards, Sviatoslav Sydorenko Software Hacker @ Ansible Core --- https://useplaintext.email/ () ascii ribbon campaign - against html e-mail /\ www.asciiribbon.org - against proprietary attachments ---

+1 -- Cooper Ry Lees [e] me@cooperlees.com [m] +1 (650) 798 7815 [w] http://cooperlees.com/ On Mon, May 24, 2021 at 9:27 AM Dustin Ingram <di@python.org> wrote:

I like this idea. The advisory repo looks like it's being kept up to date by https://github.com/osv-robot which as far as I can tell looks like a Google-run bot. Is the source for that bot available somewhere? Will a non-Googler be able to continue to maintain this repo if Google chooses to stop sponsoring the work? - e On 2021-05-24 09:27, Dustin Ingram wrote:

Great question, would you mind asking it at https://discuss.python.org/t/proposing-a-community-maintained-database-of-py... instead? If not, do you mind if I copy/paste it there for the benefit of folks not on this private mailing list? On Mon, May 24, 2021 at 6:08 PM Elana Hashman <ehashman@debian.org> wrote:

(I responded to Elana's questions here: https://discuss.python.org/t/proposing-a-community-maintained-database-of-py... ) On Mon, May 24, 2021 at 6:31 PM Dustin Ingram <di@python.org> wrote:

On Mon, May 24, 2021 at 6:28 PM Dustin Ingram <di@python.org> wrote:
+1 -- Warm regards, Sviatoslav Sydorenko Software Hacker @ Ansible Core --- https://useplaintext.email/ () ascii ribbon campaign - against html e-mail /\ www.asciiribbon.org - against proprietary attachments ---
participants (12)
-
Bernat Gabor
-
Brett Cannon
-
Cooper Ry Lees
-
Dustin Ingram
-
Elana Hashman
-
Filipe Laíns
-
Henry Schreiner
-
Matthieu Darbois
-
Sviatoslav Sydorenko
-
Thea Flowers
-
Thomas Kluyver
-
Trishank Kuppusamy