Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

csaf-poc/csaf_distribution: repo moved #905

Open
Tracked by #580
tschmidtb51 opened this issue Oct 28, 2024 · 3 comments
Open
Tracked by #580

csaf-poc/csaf_distribution: repo moved #905

tschmidtb51 opened this issue Oct 28, 2024 · 3 comments
Assignees
Labels
dependencies Pull requests that update a dependency file no-stale Denotes an issue or PR that should be preserved from going stale.

Comments

@tschmidtb51
Copy link

tschmidtb51 commented Oct 28, 2024

For your awareness:

As the tools are not a PoC (even since the first release), the long overdue change was conducted: The repo https://github.com/csaf-poc/csaf_distribution moved to https://github.com/gocsaf/csaf. The old URL can still be used for a couple month before it is sunsetted for security reasons.
Also, the license changed from MIT to Apache 2.0 (on the main branch, there is no new release yet).

Currently, that is mentioned in

"github.com/csaf-poc/csaf_distribution/v3", # MIT - https://github.com/csaf-poc/csaf_distribution/blob/main/LICENSES/MIT.txt

I guess that this is imported through Trivy so there is the possibility that you might not need to change anything.

@paralta
Copy link
Contributor

paralta commented Oct 30, 2024

@tschmidtb51 Thanks for highlighting this migration!

As you mentioned, this is a indirect dependency for us. I noticed that this issue is already being tracked in Trivy, so we will wait for the dependency bump in that repository.

@thiha-min-thant
Copy link

Hi @paralta , could you please assign to me? Thanks!

@paralta
Copy link
Contributor

paralta commented Oct 31, 2024

@thiha-min-thant thanks for your interest in contributing!

We have a bot to manage our dependencies, which should be enough to cover this. However, if there are some breaking changes in the Trivy update, we need to fix those manually. Please feel free to assign yourself to this issue if you want to cover any fixes required 😄

@ramizpolic ramizpolic added dependencies Pull requests that update a dependency file no-stale Denotes an issue or PR that should be preserved from going stale. labels Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file no-stale Denotes an issue or PR that should be preserved from going stale.
Projects
None yet
Development

No branches or pull requests

4 participants