pypa / advisory-database

Advisory database for Python packages published on pypi.org
Creative Commons Attribution 4.0 International
254 stars 60 forks source link

non-vulnerable versions found in affected versions list PYSEC-2021-878 #179

Closed dfioravanti closed 8 months ago

dfioravanti commented 8 months ago

Hello everyone, the list of affected versions for PYSEC-2021-878 includes every version ever released. Even if the advisory note says that it was packed in 1.2.3. From what I can tell this was indeed fixed, see here. Would it be possible to fix the affected list? It triggers out security check in the CI for no good reason

oliverchang commented 8 months ago

Thank you for the report and for helping make this database more accurate! I've fixed this in https://github.com/pypa/advisory-database/commit/b8d4dc79ca293237cfa97e67fff5543a42c9bfde