ZOSOpenTools / meta

Meta repository to tie together the various underlying z/OS Open Source tools repositories here
https://zosopentools.github.io/meta/
Apache License 2.0
37 stars 25 forks source link

Provide a way to ignore or add vulnerabilities to those detected by osv.dev #775

Open IgorTodorovskiIBM opened 4 weeks ago

IgorTodorovskiIBM commented 4 weeks ago

Sometimes osv.dev API returns the wrong vulnerabilities (e.g. https://github.com/google/osv.dev/issues/2041) or does not return vulnerabilities when they in fact exist.

We should have a mechanism which allows us to maintain our own list to be able to correct any issues with osv.dev.