aboutcode-org / aboutcode-org/vulnerablecode

Gitlab data source damages package versions

未關閉
#2,411 4 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

This is seen in https://public.vulnerablecode.io/advisories/todos/bc2bc6bf-eeb8-49ea-ad03-76eae234ceb2/package/curate/

Here Gitlab transformed the version 9.15 from upstream in 9.15.0 which is still technically the same, BUT does not exist in PyPI https://pypi.org/project/pgadmin4/#history

This is from https://gitlab.com/gitlab-org/security-products/gemnasium-db/-/blob/master/pypi/pgadmin4/CVE-2026-7813.yml

@dbolkensteyn FYI there is something weird in your advisory data (both gemnasium AND the public open source one)

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。