Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

back2source: Run d2d analysis on many projects #1437

Open
8 tasks done
pombredanne opened this issue Nov 4, 2024 · 2 comments
Open
8 tasks done

back2source: Run d2d analysis on many projects #1437

pombredanne opened this issue Nov 4, 2024 · 2 comments
Assignees

Comments

@pombredanne
Copy link
Member

pombredanne commented Nov 4, 2024

For each of the ecosystems below, we should define a set of interesting projects then analyze, and then review results for accuracy

The high level steps are:

  • Collect a list of PURLs and download URL pairs
  • Run the d2d scans
  • Collect and review issues and accuracy
  • Fix bugs and run again
  • Eventually find issues build a report of these and reach out to projects for key issues

The ecosystems to consider are:

@pombredanne pombredanne converted this from a draft issue Nov 4, 2024
@pombredanne pombredanne changed the title Run d2d analysis on many projects back2source: Run d2d analysis on many projects Dec 12, 2024
tdruez added a commit that referenced this issue Jan 7, 2025
tdruez added a commit that referenced this issue Jan 7, 2025
tdruez added a commit that referenced this issue Jan 8, 2025
tdruez added a commit that referenced this issue Jan 8, 2025
tdruez added a commit that referenced this issue Jan 9, 2025
tdruez added a commit that referenced this issue Jan 9, 2025
tdruez added a commit that referenced this issue Jan 9, 2025
@pombredanne pombredanne self-assigned this Jan 9, 2025
@pombredanne pombredanne moved this to In progress in 05-Back2Source next Jan 9, 2025
tdruez added a commit that referenced this issue Jan 9, 2025
Signed-off-by: tdruez <[email protected]>
tdruez added a commit that referenced this issue Jan 10, 2025
tdruez added a commit that referenced this issue Jan 10, 2025
tdruez added a commit that referenced this issue Jan 13, 2025
tdruez added a commit that referenced this issue Jan 14, 2025
tdruez added a commit that referenced this issue Jan 14, 2025
tdruez added a commit that referenced this issue Jan 14, 2025
tdruez added a commit that referenced this issue Jan 14, 2025
tdruez added a commit that referenced this issue Jan 14, 2025
@tdruez
Copy link
Contributor

tdruez commented Jan 17, 2025

Progress update [on Jan 25 2024]

Reports available for:

XLSX files @ https://github.com/aboutcode-org/back2source-data/tree/main/reports/2025-01-17

Next: "Collect and review issues and accuracy"

@pombredanne How do you want to proceed for the "review" part?

@pombredanne
Copy link
Member Author

Next: "Collect and review issues and accuracy"

@pombredanne How do you want to proceed for the "review" part?

@tdruez @AyanSinhaMahapatra the review consist in:

  1. looking at all discrepancies with a TODO/REVIEW status
  2. Fix most problems, or enter issues for larger more complex problems
  3. Collect a clean set of issues and determine if these are things we could report upstream as problems
    3.1. ideally, we would want to determine unknown bundled packages and check for unknown vulnerabilities or license issues from these inclusions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: In progress
Development

No branches or pull requests

2 participants