aboutcode-org / aboutcode-org/vulnerablecode

Alpine: possibly wrong information is indexed

Open
#915 7 comments 1 reaction 0 assignees View on GitHub
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

As I mentioned in #801 there is an issue with the way Alpine packages are indexed.

The following example illustrates this:

https://git.alpinelinux.org/aports/tree/main/py3-jinja2/APKBUILD?id=8531e658bb1a196c87ac3e8abf0bb18022266aa5

This `APKBUILD` file says the version of the package is `2.11.3-r0`. But at line 18 there is a different version number:

```
# secfixes:
# 1.11.3-r0:
# - CVE-2020-28493
```

It looks like someone made a typo in the version number and it is *this* number that VulnerableCode seems to be using (as demonstrated in #801 ).

The solution is to do a little clean up and cross correlate this information with the Alpine package information.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.