feat: Backup of repository security advisories #475
Merged
+51
−4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
About the feature
This PR adds a new
--security-advisoriesargument. This argument is included in--all.When enabled, it grabs the repository security advisories and dumps them into a
security-advisoriesdirectory.This implements #243.
Implementation
I've copied and adapted the existing implementation of
backup_milestonestobackup_security_advisoriesas the underlying GitHub API structure is basically identical.Advisories are indexed by their
ghsa_id(GitHub Security Advisory ID), which is used as a primary key in the GitHub web URLs and also the way these advisories are commonly referred to.Testing
I've tested the code on macOS with a public repo that contains both open and closed advisories.