google / osv.dev

Open source vulnerability DB and triage service.
https://osv.dev
Apache License 2.0
1.49k stars 186 forks source link

Incorrect tooltip text on osv.dev when starting affected version is 0 #2336

Closed another-rex closed 3 months ago

another-rex commented 3 months ago

Describe the bug The tooltip text says the exact initial commit is unknown, even on entries without any commit information.

(E.g. https://osv.dev/vulnerability/GHSA-25hc-qcg6-38wj)

Expected behaviour It should say: "Unknown introduced version / All previous versions are affected". Perhaps change the word "version" to "commit" on affected ranges with commits instead of versions.

Screenshots image