Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incorrectly associated project with vuln (json-logic vs json-logic-js) #165

Open
bearswithsaws opened this issue Oct 23, 2023 · 0 comments

Comments

@bearswithsaws
Copy link

In a recent Auto assign, PYSEC-2023-209 (https://github.com/pypa/advisory-database/blob/main/vulns/json-logic/PYSEC-2023-209.yaml) in regards to a re-analysis of CVE-2021-4329, however this is in regards to a Javascript version of this library.

The yaml in the vulns folder seems to incorrectly associate pypi/json-logic with https://github.com/jwadhams/json-logic-js. Although it appears the pypi package is based off the Javascript library, these are two different repositories in two different languages.

Could the entry for PYSEC-2023-209 be removed form the database since this is not in regards to the same codebase?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant