Groups keyboard shortcuts have been updated
Dismiss
See shortcuts

Update wrong package ?

17 views
Skip to first unread message

celek ibm

unread,
Dec 7, 2023, 1:22:06 PM12/7/23
to clair-dev
Hello 
We were looking at VULN named GHSA-wrvw-hg22-4m67 and repo_name maven
We see the package of one entry is google-protobuf

We looked at GHSA-wrvw-hg22-4m67 and for the ecosystem maven we see a different package name

DO we know why the package name is not the one with repo:package ? 

"package": {
"name": "com.google.protobuf:protobuf-java",
"ecosystem": "Maven",
"purl": "pkg:maven/com.google.protobuf/protobuf-java"
},

Hank Donnay

unread,
Jan 10, 2024, 4:04:11 PM1/10/24
to clai...@googlegroups.com
I'm not following what's wrong and what's expected.
>--
>You received this message because you are subscribed to the Google Groups "clair-dev" group.
>To unsubscribe from this group and stop receiving emails from it, send an email to clair-dev+...@googlegroups.com.
>To view this discussion on the web visit https://groups.google.com/d/msgid/clair-dev/b0470e35-2e22-4426-9da4-458112d66f0bn%40googlegroups.com.

--
hank

Reply all
Reply to author
Forward
0 new messages