aboutcode-org / aboutcode-org/vulnerablecode

We do not collect the affected range for Gitlab advisories

Open
#2,412 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

See https://public.vulnerablecode.io/advisories/todos/1e80217b-9032-4276-8e5b-170de8ebf750/package/curate/

and https://public.vulnerablecode.io/advisories/packages/gitlab/maven/org.bouncycastle/bcprov-debug-jdk14/CVE-2025-14813

Upstream has these ranges:
https://gitlab.com/gitlab-org/advisories-community/-/blob/main/maven/org.bouncycastle/bcprov-debug-jdk14/CVE-2025-14813.yml
```
affected_range: "[1.59.0,1.80.1],[1.82.0,1.84.0),[1.81.0,1.81.0]"
fixed_versions:
- "1.84.0"
```

- affected_range is missing
- These are subject to the #2411 issue too, but we should collect the affected range
- version `1.84.0` is reported as a ghost because there is no such version upstream
- https://public.vulnerablecode.io/packages/v2/pkg:maven/org.bouncycastle/bcprov-debug-jdk14@1.84.0?search=pkg:maven/org.bouncycastle/bcprov-debug-jdk14@1.84.0
- https://repo1.maven.org/maven2/org/bouncycastle/bcprov-debug-jdk14/1.84/

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.