Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

15.1.0 still marked as vulnerable by Sonatype OSSIndex #203

Open
janpio opened this issue Aug 11, 2022 · 0 comments
Open

15.1.0 still marked as vulnerable by Sonatype OSSIndex #203

janpio opened this issue Aug 11, 2022 · 0 comments

Comments

@janpio
Copy link

janpio commented Aug 11, 2022

https://rustsec.org/advisories/RUSTSEC-2020-0096.html was fixed as part of 15.1.0. Unfortunately Sonatype OSSIndex, a vulnerability registry, still reports that version as vulnerable with exactly this vulnerability: https://ossindex.sonatype.org/component/pkg:cargo/im@15.1.0 This data set for example is used for cargo pants but also their commercial vuln scanner product - which is why we get emails from users and customers about problems in our code.

I opened an issue with their repository where such data problems should be reported, but until now have not heard back in any way: OSSIndex/vulns#314

I wanted to let you know of this problem, which of course is not your fault in any way.

(Depending on Sonatype does things, it could be that it would go away with a 15.1.1 being release, but I can not guarantee that either - maybe they need to manually add the "max" version for a vuln and just did not do that yet with this one 🤷 )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant