Skip to content

Importers without a vulnerable package list #449

Description

@Hritik14

#436 deprecates the concept of fixed_package and now only the vulnerable packages are entered into the database. Many data sources do not provide with a list of vulnerable packages and only provide a fixed version.
Currently affected importers:

Future affected importers:

We cannot simply ignore these data sources. One approach would be to flag all the versions before the provided fixed version as vulnerable and enter those in the database. The meaning of only a fixed version could further be clarified at the data source's end.
This needs to be further discussed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions