Re: [OE-core] Cve fetcher update

2023-03-28 Thread Marta Rybczynska
On Wed, Feb 22, 2023 at 11:08 AM Marta Rybczynska via lists.openembedded.org
 wrote:

>
>
> On Tue, Feb 21, 2023 at 2:47 PM Ross Burton  wrote:
>
>> Hi Marta,
>>
>> > On 21 Feb 2023, at 13:20, Marta Rybczynska 
>> wrote:
>> > I'm finishing the new fetcher for cve check using the 2.0 NVD API. Will
>> need testers to check as many configurations as possible before we switch
>> the format.
>> >
>> > The current estimate is this week, hoping that the real life doesn't
>> interfere.
>> >
>> > Good news for all users is that nothing changes for you. Results should
>> be compatible. The one noticeable thing is that the complete fetch is
>> longer than before.
>>
>> Awesome, thanks Marta.  I’ll happily review and test the code.
>>
>> How long is a complete fetch now?  My very rough testing when I first
>> looked at the new API suggested 30 minutes for a full sync.
>>
>>
> Thanks Ross. The fetcher now has the recommended 6 seconds wait so it is
> long - but a similar time you had (around 30 min). It seems that in
> practice it does not change much - the rate limiting is on the server side.
> This being said, there is only my instance now, when there will be many
> more, it could change.
>
>
>
Hello Ross,
Have you finished your review? The new version that is under test in my
systems right now is using urllib. I'm wondering what was your other
feedback.

Kind regards,
Marta

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#179229): 
https://lists.openembedded.org/g/openembedded-core/message/179229
Mute This Topic: https://lists.openembedded.org/mt/97108178/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



Re: [OE-core] Cve fetcher update

2023-02-22 Thread Marta Rybczynska
On Tue, Feb 21, 2023 at 2:47 PM Ross Burton  wrote:

> Hi Marta,
>
> > On 21 Feb 2023, at 13:20, Marta Rybczynska  wrote:
> > I'm finishing the new fetcher for cve check using the 2.0 NVD API. Will
> need testers to check as many configurations as possible before we switch
> the format.
> >
> > The current estimate is this week, hoping that the real life doesn't
> interfere.
> >
> > Good news for all users is that nothing changes for you. Results should
> be compatible. The one noticeable thing is that the complete fetch is
> longer than before.
>
> Awesome, thanks Marta.  I’ll happily review and test the code.
>
> How long is a complete fetch now?  My very rough testing when I first
> looked at the new API suggested 30 minutes for a full sync.
>
>
Thanks Ross. The fetcher now has the recommended 6 seconds wait so it is
long - but a similar time you had (around 30 min). It seems that in
practice it does not change much - the rate limiting is on the server side.
This being said, there is only my instance now, when there will be many
more, it could change.

Kind regards,
Marta

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#177563): 
https://lists.openembedded.org/g/openembedded-core/message/177563
Mute This Topic: https://lists.openembedded.org/mt/97108178/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



Re: [OE-core] Cve fetcher update

2023-02-21 Thread Ross Burton
Hi Marta,

> On 21 Feb 2023, at 13:20, Marta Rybczynska  wrote:
> I'm finishing the new fetcher for cve check using the 2.0 NVD API. Will need 
> testers to check as many configurations as possible before we switch the 
> format.
> 
> The current estimate is this week, hoping that the real life doesn't 
> interfere.
> 
> Good news for all users is that nothing changes for you. Results should be 
> compatible. The one noticeable thing is that the complete fetch is longer 
> than before.

Awesome, thanks Marta.  I’ll happily review and test the code.

How long is a complete fetch now?  My very rough testing when I first looked at 
the new API suggested 30 minutes for a full sync.

Cheers,
Ross
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#177498): 
https://lists.openembedded.org/g/openembedded-core/message/177498
Mute This Topic: https://lists.openembedded.org/mt/97108178/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



[OE-core] Cve fetcher update

2023-02-21 Thread Marta Rybczynska
Hello all,
I'm finishing the new fetcher for cve check using the 2.0 NVD API. Will
need testers to check as many configurations as possible before we switch
the format.

The current estimate is this week, hoping that the real life doesn't
interfere.

Good news for all users is that nothing changes for you. Results should be
compatible. The one noticeable thing is that the complete fetch is longer
than before.

Kind regards,
Marta

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#177495): 
https://lists.openembedded.org/g/openembedded-core/message/177495
Mute This Topic: https://lists.openembedded.org/mt/97108178/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-