Skip to content

multiple GHSA CVEs with patched versions in affected list #5184

@Tom-v-G

Description

@Tom-v-G

Some OSV json files containing GitHub advisories available via www.googleapis.com seem to include the patched versions in the affected versions list. I have included two examples containing this issue below:

The references list in the JSON files do contain urls linking to the patched releases, so the information to correctly parse the fixed versions was avaiable. Is this an issue with OSV, or with GHSA? Or is the information avaiable via googleapis not up to date?
The files available via https://api.osv.dev/ do denote the right fixed versions.

Thank you in advance,

Tom

Metadata

Metadata

Assignees

Labels

data qualityIssues with data quality

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions