Skip to content

Add vulnerabilities to the PyPI JSON API - #1357

Draft
gerrod3 wants to merge 2 commits into
pulp:mainfrom
gerrod3:cr/pypi-json-vulnerabilities
Draft

Add vulnerabilities to the PyPI JSON API#1357
gerrod3 wants to merge 2 commits into
pulp:mainfrom
gerrod3:cr/pypi-json-vulnerabilities

Conversation

@gerrod3

@gerrod3 gerrod3 commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Serve Warehouse-shaped vulnerability data from stored OSV reports, and let remotes opt in to scan the new repository version after sync.

Assisted By: Cursor Grok 4.6

📜 Checklist

  • Commits are cleanly separated with meaningful messages (simple features and bug fixes should be squashed to one commit)
  • A changelog entry or entries has been added for any significant changes
  • Follows the Pulp policy on AI Usage
  • (For new features) - User documentation and test coverage has been added

See: Pull Request Walkthrough

Serve Warehouse-shaped vulnerability data from stored OSV reports, and
let remotes opt in to scan the new repository version after sync.

Assisted By: Cursor Grok 4.6

Co-authored-by: Cursor <cursoragent@cursor.com>
@gerrod3
gerrod3 force-pushed the cr/pypi-json-vulnerabilities branch from e72f601 to 5b93bae Compare August 27, 2026 13:48
Comment thread pulp_python/app/utils.py Outdated
Filter OSV reports by repository version so another index cannot show
vulns until it is scanned. Move the Warehouse trim helper out of
Django-backed utils so unit tests collect without loading apps.

Assisted By: Cursor Grok 4.6

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions github-actions Bot added multi-commit Add to bypass single commit lint check no-changelog labels Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

multi-commit Add to bypass single commit lint check no-changelog no-issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant