Skip to content

Ghost package should not be reported as a fix for vulnerability #1650

Description

@TG1999

https://public.vulnerablecode.io/packages/pkg:maven/log4j/log4j@1.2.8?search=maven/log4j

Reports https://public.vulnerablecode.io/packages/pkg%3Amaven/log4j/log4j%402.17.0?search=pkg:maven/log4j/log4j@2.17.0 as the latest non vulnerable version of log4j. But this is a ghost package. We should not report ghost package as fix/non vulnerable for anything.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions