aboutcode-org / aboutcode-org/vulnerablecode
Gitlab data source damages package versions
Aperta
- Lingua principale
- Python
- Stelle
- 702
- Fork
- 328
- Merge medio
- 3g 8h
- PR unite (30g)
- 3
Descrizione
This is seen in https://public.vulnerablecode.io/advisories/todos/bc2bc6bf-eeb8-49ea-ad03-76eae234ceb2/package/curate/
Here Gitlab transformed the version 9.15 from upstream in 9.15.0 which is still technically the same, BUT does not exist in PyPI https://pypi.org/project/pgadmin4/#history
This is from https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/pypi/pgadmin4/CVE-2026-7813.yml
@dbolkensteyn FYI there is something weird in your advisory data (both gemnasium AND the public open source one)
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Valutazione
Questa issue non è ancora stata valutata.