ossf / osv-schema

Open Source Vulnerability schema.
https://ossf.github.io/osv-schema/
Apache License 2.0
186 stars 84 forks source link

Clarify PURL requirements. #300

Closed oliverchang closed 3 weeks ago

oliverchang commented 1 month ago

PURLs should not include the @version component when used in OSV.

affected[].ranges[] should be used for this purpose.

oliverchang commented 1 month ago

LGTM. Do you want to explicitly state anything about the other components?

I'm not sure we have much to add there. Are there any qualifiers in particular you'd want to see not be included in PURLs here?