osv index and vuln discovery

48 views
Skip to first unread message

Mehdi Karimi

unread,
Aug 4, 2021, 6:56:46 PM8/4/21
to osv-discuss
How many of the oss packages are indexed or actually fuzzed?! 
Is this a starter project? 
For example, I am trying to query expat, version 2.2.5 and I see nothing returned! however, from the expat site, I see there is vuln with 2.2.5. 

myjson = {"version": "2.2.5", "package": {"name": "expat", "ecosystem": "OSS-Fuzz"}}
x = requests.post(url, json = myjson)
print(x.text)

I also tried packages listed below with the PyPI ecosystem but nothing returns!
Reply all
Reply to author
Forward
0 new messages