Skip to content
This repository has been archived by the owner on Jan 19, 2023. It is now read-only.

Missing Vulnerable information #312

Open
VASAVI512 opened this issue Jul 26, 2022 · 3 comments
Open

Missing Vulnerable information #312

VASAVI512 opened this issue Jul 26, 2022 · 3 comments
Labels
advisory An advisory missing from the OSS Index database

Comments

@VASAVI512
Copy link

Hello,

Please find the details below. Though vulnerability is shown in NVD, its not captured in Sonatype.
example: Purl url is not showing any vulnerable information in sonatpe search " https://ossindex.sonatype.org/search"
Let us know why is it not showing any information in here.

Advisory details

   "name" : "Flask-Cors",
    "version" : "3.0.6",
    "purl" : "pkg:conda/[email protected]_0-win-64",
URL: https://flask-cors.corydolphin.com/
  format: <Conda>

Regards,
Vasavi

@VASAVI512 VASAVI512 added the advisory An advisory missing from the OSS Index database label Jul 26, 2022
@ken-duck
Copy link
Contributor

Sorry for the delay. We are still working on developing processes to handle issues, and I have been away for a while (catching up now)!

This issue has been passed to the research team on our internal tracking system, and I will report back here once more is known.

@ken-duck
Copy link
Contributor

Very sorry for the delay. As you may have noticed, a number of issues have fallen through the cracks, and we are in the process of catching up and cleaning things up.

Thank you for your report. We are migrating to a new email-based reporting system in order to better mesh with our internal processes, which will allow us to be more reactive to our users. I have moved your request to the internal tracking system and the research team will look into the issue shortly.

If you notice further issues or would like to follow up on this one, please email [email protected]

@ken-duck
Copy link
Contributor

One added thing. OSS Index does not currently handle PURLs with postfixes after the version number like that supplied in your example.

pkg:conda/[email protected]_0-win-64

The version as expected by OSS Index is as follows:

https://ossindex.sonatype.org/component/pkg:conda/[email protected]

I am adding a story to our internal tracking to look into handling these sorts of postfixes in the future.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
advisory An advisory missing from the OSS Index database
Projects
None yet
Development

No branches or pull requests

2 participants