Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Better Maven package support #361

Open
kosztyua opened this issue Jun 27, 2024 · 5 comments
Open

Better Maven package support #361

kosztyua opened this issue Jun 27, 2024 · 5 comments
Labels
enhancement New feature or request

Comments

@kosztyua
Copy link

What would you like to be added:
Maven packages seems to completely miss deprecation and end-of-life status. An example here is log4j 1.x, that shows no deprecated versions https://www.xeol.io/explorer/package/Maven/log4j%3Alog4j. Randomly checking it seems Maven packages do not have this correctly recorded, but also I could not find a way to reliable get this from mvnrepository. However, it is correctly recorded on endoflife.date, but that API does not have pURL support currently.

So I assume based on this I would start a brainstorm thread here on how to solve it, I would even contribute code if someone has an idea.

Why is this needed:
Almost missed log4j-1.2.17.jar. Xeol does not report it, trivy says "affected" status and grype says "not-fixed" which are often filtered/ignored in productions where scaling is needed

@kosztyua kosztyua added the enhancement New feature or request label Jun 27, 2024
@kosztyua
Copy link
Author

Bump? Any idea? I am happy to contribute code if someone has an idea

@kosztyua
Copy link
Author

So while digging the xeol code I found the UsePURLs: true controlled by the "using-purls" config value. But even setting this false did not bring different results.

@noqcks
Copy link
Collaborator

noqcks commented Aug 12, 2024

For some reason I didn't see this or get notified about this issue.

The reason is the underlying data. Right now we dont collect EOL information for Maven packages. To support this we would need to add this to the data.

I have all the scraping logic for maven central, I just need to add it to our data collection lambdas that run.

@kosztyua
Copy link
Author

Thank you for the update and no worries 🙏 Will keep an eye out for any updates, we started utilizing your great tool in all our pipelines.

@eyups
Copy link

eyups commented Oct 21, 2024

Hi,

Is there any timeline for that? Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants