aboutcode-org / aboutcode-org/vulnerablecode

Gitlab data source damages package versions

Open
#2,411 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

This is seen in https://public.vulnerablecode.io/advisories/todos/bc2bc6bf-eeb8-49ea-ad03-76eae234ceb2/package/curate/

Here Gitlab transformed the version 9.15 from upstream in 9.15.0 which is still technically the same, BUT does not exist in PyPI https://pypi.org/project/pgadmin4/#history

This is from https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/pypi/pgadmin4/CVE-2026-7813.yml

@dbolkensteyn FYI there is something weird in your advisory data (both gemnasium AND the public open source one)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.