Closed
Description
GSoC 2024 has been officially announced and the schedule is up here:
https://developers.google.com/open-source/gsoc/timeline
We'll want to have some viable ideas nailed down around the end of January for when Python puts in an org application. But the first step to this is brainstorming on all ideas (including ones that may not work out for various reasons) so feel free to just throw ideas around here and we'll narrow it down later.
Some wishlist items off the top of my head to get the discussion started:
- Improved PURL/SBOM support and other input data quality tools
- helping people annotate SBOMs with PURL data or otherwise improve SBOM quality
- improved PURL support for our language parsers (some of this may happen before gsoc but I suspect there will still be work to do by then)
- we'd previously discussed using additional metadata (e.g. from language package repositories) to improve scan quality but didn't get a taker for that gsoc project, so it might get rolled into a new one
- Improved Triage tooling:
- warning when triage goes "out of date"
- improved support for using multiple triage files
- improved tooling and guidance (documentation) on how to triage, how to share triage, how to use shared triage. I suspect that in writing documentation people will find a few more gaps.