Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Module no longer works, sensiolabs/security-checker is abandoned #57

Open
chillu opened this issue Jan 31, 2021 · 8 comments
Open

Module no longer works, sensiolabs/security-checker is abandoned #57

chillu opened this issue Jan 31, 2021 · 8 comments

Comments

@chillu
Copy link
Contributor

chillu commented Jan 31, 2021

We need to start hosting our own security checking tool, or add the ability to run this with a local CLI tool - see https://github.com/sensiolabs/security-checker

@chillu
Copy link
Contributor Author

chillu commented Jan 31, 2021

As a secondary effect, this will slightly increase queue wait times when running through queuedjobs, since the domain has been shut down and API requests will hold up a queue worker until they time out.

@spekulatius
Copy link
Member

Hey @chillu

thanks for the update, didn't know about this.

I wonder what implications come from adding a golang-based package as requirement. Wonder if everyone is on board with this.

Cheers,
Peter

@chillu
Copy link
Contributor Author

chillu commented Feb 11, 2021

Hey Peter, just letting you know that we're discussing this internally (because we need to figure out both how we deal with this for the OSS community as well as our own Platform customers). This might or might not be the same solution, we'll stay in touch.

@spekulatius
Copy link
Member

Hey Ingo,

yeah, that's fine. Just keep me in the loop how you plan resolve it.

Cheers,
Peter

@jcop007
Copy link

jcop007 commented Apr 16, 2021

Hi @chillu

Any update on what the future plan is for this module?

Thanks,
Jonathan

@chillu
Copy link
Contributor Author

chillu commented Apr 30, 2021

@jcop007 Keen to implement the Sensio golang library approach as an alternative to API calls? So change the update job to using shell_exec(). Pull requests welcome.

@maxime-rainville
Copy link
Collaborator

Looks like packagist now has a Security Advisory API ... that seems like perfect replacement for sensio labs.

It would also align this module's warnings to the one provided by composer.

@GuySartorelli
Copy link
Collaborator

There's a PR to add functionality to composer that consumes that API. Probably worth just hooking into that once it's available. composer/composer#10798

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
7 participants