Skip to content

Add support for collecting GitHub/GitLab vulnerability-related issues and pull requests#2008

Open
ziadhany wants to merge 10 commits intoaboutcode-org:mainfrom
ziadhany:parse-issues-PR
Open

Add support for collecting GitHub/GitLab vulnerability-related issues and pull requests#2008
ziadhany wants to merge 10 commits intoaboutcode-org:mainfrom
ziadhany:parse-issues-PR

Conversation

@ziadhany
Copy link
Collaborator

@ziadhany ziadhany commented Oct 23, 2025

@ziadhany ziadhany changed the title Add support for collecting GitHub vulnerability-related issues and pull requests Add support for collecting GitHub/GitLab vulnerability-related issues and pull requests Feb 12, 2026
ziadhany added 6 commits March 5, 2026 17:30
…ll requests

Add tests for this functionality

Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Rename the pipeline name
Add the missing pygithub dependency

Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
… the code

Signed-off-by: ziad hany <ziadhany2016@gmail.com>
ziadhany added 3 commits March 6, 2026 19:51
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Use the VulnerableCodeBaseImporterPipelineV2 for collection

Signed-off-by: ziad hany <ziadhany2016@gmail.com>
@ziadhany ziadhany requested a review from keshav-space March 7, 2026 01:11
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Copy link
Member

@keshav-space keshav-space left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @ziadhany, let's move these pipeline here https://github.com/aboutcode-data/vulnerablecode-vcs-collector similar to how we do in https://github.com/aboutcode-org/aboutcode-mirror-nuget-catalog. We can store the list CVE, vcs_url, refrence in a json file per project. And VulnerableCode should have single importer pipeline to import these from there. We will do the same for our existing fix commit collection pipeline those will also moved to github workflow pipeline.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants