Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    Vulnerability Version Syntax

    Scheduled Pinned Locked Moved Support
    securitynugetproget
    2 Posts 2 Posters 13 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? This user is from outside of this forum
      Guest
      last edited by

      Hi,

      Vulnerability feeds have multiple ways to version vulnerable libraries, such as:

      1. 5.5.28
      2. <0.9.1
      3. =0.5.0 <0.5.2 || >=0.4.0 <0.4.2

      4. 1.3.0-beta.1 <1.3.0-rc.1

      5. 1.0.1, 1.0.2

      Can you please clarify what syntax is supported / expected here? There are examples of exact version (1 above) and less than a version (2 above) in the Vor integration video, but nothing is documented around what is supported for manual entries.

      Thank you

      James

      Product: ProGet
      Version: 4.6.4

      1 Reply Last reply Reply Quote 0
      • benB Offline
        ben inedo-engineer
        last edited by

        A vulnerability version range can be:

        • the literal string (any)
        • empty string (equivalent to (any))
        • single
        • single, single
        • single, single, single
        • single, single, single, single
        • etc.

        A single vulnerability version range can be:

        • version
        • >version
        • >=version
        • <version
        • <=version
        • >version <version
        • >=version <version
        • >version <=version
        • >=version <=version

        The format of version is defined by the feed type.

        1 Reply Last reply Reply Quote 0

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        • 1 / 1
        • First post
          Last post
        Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation