Discussion:
Bug#1034575: ITP: cve-bin-tool -- The CVE Binary Tool is a free, open source tool to help you find known vulnerabilities in software, using data from the National Vulnerability Database (NVD) list of Common Vulnerabilities and Exposures (CVEs).
(too old to reply)
jarebear6expepjozn6rakjq5iczi3irqwphcvbswgkahd6b6twnxxid
2023-04-18 18:10:01 UTC
Permalink
Package: wnpp
Severity: wishlist
Owner: jarebear6expepjozn6rakjq5iczi3irqwphcvbswgkahd6b6twnxxid <***@4xvk.com>
X-Debbugs-Cc: debian-***@lists.debian.org, ***@4xvk.com

* Package name : cve-bin-tool
Version : 3.2.0
Upstream Author : Teri Oda <***@intel.com>
* URL : https://github.com/intel/cve-bin-tool
* License : GPL
Programming Lang: Python
Description : The CVE Binary Tool is a free, open source tool to help you find known vulnerabilities in software, using data from the National Vulnerability Database (NVD) list of Common Vulnerabilities and Exposures (CVEs).

The tool has two main modes of operation:

A binary scanner which helps you determine which packages may have been included as part of a piece of software. There are 288 checkers which focus on common, vulnerable open source components such as openssl, libpng, libxml2 and expat.
Tools for scanning known component lists in various formats, including .csv, several linux distribution package lists, language specific package scanners and several Software Bill of Materials (SBOM) formats.

It is intended to be used as part of your continuous integration system to enable regular vulnerability scanning and give you early warning of known issues in your supply chain.
Sudip Mukherjee
2024-10-10 14:10:01 UTC
Permalink
Hi,

I just came across this software and found it to be very useful. Do
you have any update on the packaging status?

Please do let me know if you are stuck with something or not
interested in the packaging anymore then I can take it up.
--
Regards
Sudip
Sudip Mukherjee
2024-10-12 13:10:02 UTC
Permalink
Hi,
Having a quick look at requirements.txt VS Debian repo, to package this
python3-cvss
python3-gsutil
python3-lib4sbom
python3-lib4vex
python3-packageurl
python3-rpmfile
Thanks for the list zigo. But the main intention of my mail was to check if the ITP owner is still interested or not since there has been no progress since 18 Apr 2023.
If the ITP owner is not interestd then I can do this one ( + any other dependency) under the Debian Python team.

I guess I will wait a week for any reply, and if there is no reply by then from the owner I will assume the ITP owner is not interested anymore and take over.
--
Regards
Sudip
t***@goirand.fr
2024-10-12 14:50:01 UTC
Permalink
Post by Sudip Mukherjee
Hi,
Having a quick look at requirements.txt VS Debian repo, to package this
python3-cvss
python3-gsutil
python3-lib4sbom
python3-lib4vex
python3-packageurl
python3-rpmfile
Thanks for the list zigo. But the main intention of my mail was to check if the ITP owner is still interested or not since there has been no progress since 18 Apr 2023.
If the ITP owner is not interestd then I can do this one ( + any other dependency) under the Debian Python team.
I guess I will wait a week for any reply, and if there is no reply by then from the owner I will assume the ITP owner is not interested anymore and take over.
--
Regards
Sudip
At this point (ie: 6 months after the ITP), IMO you do not need to wait.


Thomas
Sudip Mukherjee
2024-10-12 18:00:02 UTC
Permalink
Post by t***@goirand.fr
Post by Sudip Mukherjee
Hi,
Having a quick look at requirements.txt VS Debian repo, to package this
python3-cvss
python3-gsutil
python3-lib4sbom
python3-lib4vex
python3-packageurl
python3-rpmfile
Thanks for the list zigo. But the main intention of my mail was to check if the ITP owner is still interested or not since there has been no progress since 18 Apr 2023.
If the ITP owner is not interestd then I can do this one ( + any other dependency) under the Debian Python team.
I guess I will wait a week for any reply, and if there is no reply by then from the owner I will assume the ITP owner is not interested anymore and take over.
--
Regards
Sudip
At this point (ie: 6 months after the ITP), IMO you do not need to wait.
I am sure you meant 1 year 6 months from the ITP. :D
--
Regards
Sudip
Loading...