-
Notifications
You must be signed in to change notification settings - Fork 215
Description
We need an opam PURL type for OCaml packages... it has been listed forever, but does not have a definition.
@LaurentGoderre has started this PR with @kit-ty-kate just before we updated to use a more structured approach... This may need some love to convert to the new JSON format:
Also the Ocaml announced the formation of security team at https://ocaml.org/changelog/2025-10-03-security-team and is starting a new vulnerability database at https://github.com/ocaml/security-advisories
@hannesm gentle ping as it would be awesome that your upcoming OSV advisories are properly keyed by PURL (which is supported and encouraged to use in OSV and is also part of the latest rev 5.2 of the CVE schema)
Also it would wonderful to list the proper PURL of an opam package on its web page like at https://ocaml.org/p/odoc/3.1.0
FYI, Maven Central, Rust crates.io and PHP packagist already do list PURLs on each package web page.