Groups
Groups
Sign in
Groups
Groups
osv-discuss
Conversations
About
Send feedback
Help
unexpected results for a specific commit ID
21 views
Skip to first unread message
Egon Kocjan
unread,
Apr 28, 2025, 1:56:41 PM
Apr 28
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to osv-discuss
Hi
When running OSV Scanner 2.0.1 on this osv-scanner.json lockfile:
{"results":[{"source":{},"packages":[{"package":{"name":"
https://github.com/jquery/jquery-mou...@3.0.6
","commit":"a06ef4e1a127795606642c55e22d4f2945edc061"}}]}]}
I get many CVEs for a seemingly unrelated project
https://github.com/librenms/librenms
, for example
https://osv.dev/vulnerability/CVE-2024-47523
Is there any info how vulns are tagged with commit IDs? This one looks like it's not tagged correctly.
Regards
Egon
Egon Kocjan
unread,
Apr 29, 2025, 5:04:24 PM
Apr 29
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to osv-discuss
Sorry for spam (I missed github repo), posted issue here instead:
https://github.com/google/osv.dev/issues/3398
Reply all
Reply to author
Forward
0 new messages