ossf/alpha-omega

@latest doesn't work if it doesn't have an API key

AOrps opened this issue · 2 comments

AOrps commented

Potential Improvements

  • Listing Versions of Software

@AOrps Could you elaborate on this issue?

Suggestion include
What the issue is?
How do you recreate the issue?
Areas of interest in the solution
Potential solutions
Any relevant links or commits

AOrps commented

Unsure the best way to move forward on this:

More a documentation enhancement if anyone can work on this:

  • @latest will not work without an API KEY (librariesIO Token) because it infers the latest version, perhaps this can just be an addition onto the analyzer documentation.

Instead, an interesting functionality enhancement would be to list all versions of a package provided by librariesIO to see the vulnerabilities from version to version