-
Outcome
-
Resolution: Done
-
Normal
-
None
-
None
-
None
-
False
-
Inspired by another discussion, it seems like we may not have a way to discover the index (repository) a python package is installed from.
We currently assume everything is installed from pypi.org, which is not correct but good enough if we're only considering public/OSV data. If Red Hat starts producing VEX data for python packages, we'll need to be able to identify which packages come from a Red Hat index.
- is cloned by
-
CLAIRDEV-216 claircore: java: can repository information be discovered?
-
- Refinement
-