You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
depot_tools/metadata
Jordan Brown e42fac3e9c [dependency_metadata] Allow descriptions for CVEs
This adds a new way to report CVEs that includes an accompanying
description. It also adds a new validation check that ensures that the
CVE description is present for every entry listed in the 'Mitigated:'
field.

Bug: b/392026683
Change-Id: Ie55595970b49d705ac532f1f8c41ff47d959f56c
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/tools/depot_tools/+/6211644
Auto-Submit: Jordan Brown <rop@google.com>
Reviewed-by: Jiewei Qian <qjw@chromium.org>
Commit-Queue: Jiewei Qian <qjw@chromium.org>
3 months ago
..
fields [dependency_metadata] Allow descriptions for CVEs 3 months ago
tests [dependency_metadata] Allow descriptions for CVEs 3 months ago
LICENSE_OWNERS Add clear documentation to license_allowlist.py 3 months ago
OWNERS Updating presubmit to check license is a valid spdx identifier. 5 months ago
PRESUBMIT.py [ssci] PEP8 formatting for metadata directory 2 years ago
README.md [ssci] Script to run validation on all metadata files 2 years ago
SECURITY_TEAM_OWNERS Updating presubmit to check license is a valid spdx identifier. 5 months ago
__init__.py Define main metadata validation functions 2 years ago
dependency_metadata.py [dependency_metadata] Allow descriptions for CVEs 3 months ago
discover.py metadata: sort discovered files and validation messages 1 year ago
parse.py [dependency_metadata] Allow descriptions for CVEs 3 months ago
scan.py metadata: sort result summary 1 year ago
validate.py Add `is_open_source_project` to metadata validation 4 months ago
validation_result.py metadata: add line number reporting 9 months ago

README.md

Validation for Chromium's Third Party Metadata Files

This directory contains the code to validate Chromium third party metadata files, i.e. README.chromium files.

Prerequisites

  1. Have the Chromium source code checked out on disk
  2. Ensure you've run gclient runhooks on your source checkout

Run

metadata/scan.py can be used to search for and validate all Chromium third party metadata files within a repository. For example, if your chromium/src checkout is at ~/my/path/to/chromium/src, run the following command from the root directory of depot_tools:

vpython3 --vpython-spec=.vpython3 metadata/scan.py ~/my/path/to/chromium/src