aboutcode-org / vulnerablecode

A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
https://public.vulnerablecode.io
Apache License 2.0
543 stars 201 forks source link

Do not report ghost package as a fix for vulnerability #1679

Open keshav-space opened 2 days ago

keshav-space commented 2 days ago

UI: Package Details

Before After
Screenshot from 2024-11-20 16-02-29 Screenshot from 2024-11-20 16-02-57

UI: Vulnerability Details

Before After
Screenshot from 2024-11-20 18-18-02 Screenshot from 2024-11-20 18-18-29

UI: Package Details with Latest/Next non-vulnerable

Before After
Screenshot from 2024-11-22 13-29-56 Screenshot from 2024-11-22 13-30-10

APIv1: /api/vulnerabilities

Before After
Screenshot from 2024-11-20 18-23-45 Screenshot from 2024-11-20 18-24-25

APIv1: /api/packages

Before After
Screenshot from 2024-11-20 18-25-04 Screenshot from 2024-11-20 18-25-21

APIv2: /api/v2/packages with latest/next non-vulnerable

Before After
Screenshot from 2024-11-22 13-25-50 Screenshot from 2024-11-22 13-28-33

APIv2: /api/v2/packages with ghost fixing_vulnerabilities

Before After
Screenshot from 2024-11-22 13-31-25 Screenshot from 2024-11-22 13-34-41