Skip to content

Add support for user-specified local advisory DB #1

Description

@funnelfiasco

Right now, the offline mode falls back to the builtin advisory DB. However, there are two use cases where the user might want to reference their own DB separately from either the GitHub or builtin DB:

  1. Internally-maintained DB that may be supplemented with confidential information or used in an environment with restricted network access
  2. Testing proposed changes to the public advisory DB

This might be best implemented by treating the user-provided DB as supplemental and adding an option like --additional-db <LOCATION>. In the ideal case, it could be either an HTTPS URL or a filesystem path, although if that gets too complicated, I think a filesystem path is sufficient. The other option would be to ignore both of the GitHub and builtin DBs when a user supplies a DB location. In that case, it might be better to make it an optional argument to --offline (or have --offline builtin be a special case that uses the builtin DB before looking on the filesystem)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions