aboutcode-org / aboutcode-org/vulnerablecode

Gitlab data source damages package versions

オープン
#2,411 コメント 4 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

This is seen in https://public.vulnerablecode.io/advisories/todos/bc2bc6bf-eeb8-49ea-ad03-76eae234ceb2/package/curate/

Here Gitlab transformed the version 9.15 from upstream in 9.15.0 which is still technically the same, BUT does not exist in PyPI https://pypi.org/project/pgadmin4/#history

This is from https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/pypi/pgadmin4/CVE-2026-7813.yml

@dbolkensteyn FYI there is something weird in your advisory data (both gemnasium AND the public open source one)

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。