Currently we have: https://github.com/aboutcode-org/vulnerablecode/blob/be891173be2fbdc897116bf5aa4fc9fdc8dc4f3d/vulnerabilities/pipelines/v2_importers/vulnrichment_importer.py#L215 This would be reused at many places, so we should consider moving this as a separate library to avoid code duplication.