Skip to content

feat: add support for the Drupal ecosystem#3723

Closed
G-Rath wants to merge 3 commits into
google:masterfrom
ackama:G-Rath-patch-2
Closed

feat: add support for the Drupal ecosystem#3723
G-Rath wants to merge 3 commits into
google:masterfrom
ackama:G-Rath-patch-2

Conversation

@G-Rath
Copy link
Copy Markdown
Collaborator

@G-Rath G-Rath commented Jul 29, 2025

This adds support for the (upcoming) Drupal ecosystem as defined in ossf/osv-schema#372 - notably, this ecosystem uses the same version structure as Packagist and can have an optional :7 suffix for denoting Drupal v7 advisories

@github-actions
Copy link
Copy Markdown

This pull request has not had any activity for 60 days and will be automatically closed in two weeks

@github-actions github-actions Bot added the stale The issue or PR is stale and pending automated closure label Sep 27, 2025
@jess-lowe jess-lowe added backlog Important but currently unprioritized and removed stale The issue or PR is stale and pending automated closure labels Oct 2, 2025
@G-Rath
Copy link
Copy Markdown
Collaborator Author

G-Rath commented Nov 6, 2025

This is no longer needed as we're not going to use a dedicated ecosystem for Drupal

@G-Rath G-Rath closed this Nov 6, 2025
@G-Rath G-Rath deleted the G-Rath-patch-2 branch November 6, 2025 00:40
@valentijnscholten
Copy link
Copy Markdown

valentijnscholten commented Jan 3, 2026

@G-Rath Could you let us know what happened here? I think I am seeing vulnerabilities from the drupal database, i.e. https://osv.dev/vulnerability/DRUPAL-CONTRIB-2023-052. However the Drupal database (or ecosystem) is not mentioned on:

My feeling is that the Drupal database is mirrored/ingested, but it's been made part of the Packagist ecosystem?

I looked for other PRs but I am struggling to find the one that actually adds this.

@G-Rath
Copy link
Copy Markdown
Collaborator Author

G-Rath commented Jan 3, 2026

@valentijnscholten yes that's correct, we're using the Packagist ecosystem - if you look at the advisory the source is the Drupal advisory database.

We added the db to prod in #4394 and you can read more about it in our blog post

Happy to answer any questions either on GH or in the Drupal Slack 🙂

@valentijnscholten
Copy link
Copy Markdown

Thanks. The part that I missed is that the conversion to OSV format is actually done in https://github.com/DrupalSecurityTeam/drupal-advisory-database.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backlog Important but currently unprioritized

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants