Skip to content

multiple GHSA CVEs with patched versions in affected list #5184

@Tom-v-G

Description

@Tom-v-G

Some OSV json files containing GitHub advisories available via www.googleapis.com seem to include the patched versions in the affected versions list. I have included two examples containing this issue below:

The references list in the JSON files do contain urls linking to the patched releases, so the information to correctly parse the fixed versions was avaiable. Is this an issue with OSV, or with GHSA? Or is the information avaiable via googleapis not up to date?
The files available via https://api.osv.dev/ do denote the right fixed versions.

Thank you in advance,

Tom

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions