Navigation

    Inedo Community Forums

    Forums

    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    1. Home
    2. aristo_4359
    3. Topics
    • Profile
    • Following
    • Followers
    • Topics
    • Posts
    • Best
    • Groups

    Topics created by aristo_4359

    • aristo_4359

      Incorrect Vulnerability Assesment for versions later than specified in description
      Support • • aristo_4359  

      2
      0
      Votes
      2
      Posts
      7
      Views

      atripp

      Hi @aristo_4359 , This will happen from time to time and there's no great solution to fixing it. The underlying issue is simple actually; the source data is incorrectly coded, and systems like PGVD that rely on that will display incorrect results. Since sources routinely update data (and they may fix this... if you ask), PGVD will also update the ingested data. So it becomes quite complicated to try to "override" incorrect data, even though it's so obvious from reading the description and looking at it. Without getting into too many details, here is how they encoded this at the source: "database_specific": { "last_known_affected_version_range": "< 0.19.3" } Compare this to another vulnerability at the same source, and you will see this is the correct encoding: { "last_affected": "2.0.13" } Given the infrequency that this happens, and the fact that it's an old, low-risk vulnerability (we would rate this as a "2 out of 5" on our upcoming scale FYI), we don't think it's worth worrying about. Thanks, Alana
    • aristo_4359

      Importing Conan Packages empty executions
      Support • • aristo_4359  

      3
      0
      Votes
      3
      Posts
      9
      Views

      aristo_4359

      Thank you
    • aristo_4359

      Search feed(s) for version string
      Support • • aristo_4359  

      4
      0
      Votes
      4
      Posts
      10
      Views

      stevedennis

      @aristo_4359 oh I see! The "search" function does not work by version in that case
    • aristo_4359

      Use original publish date for imported packages
      Support • • aristo_4359  

      4
      0
      Votes
      4
      Posts
      15
      Views

      aristo_4359

      I noticed this mechanism when I migrated from Artifactory to Proget in my company but only able to comment now. I would say thank you very much for you guys for addressing this, especially since it is done before the migration in my company.
    • aristo_4359

      Does npm feed support whoami?
      Support • • aristo_4359  

      4
      0
      Votes
      4
      Posts
      12
      Views

      stevedennis

      @aristo_4359 thanks for letting us know! You are the first person to inquire about it over very many years :) We'll see if anyone else is interested in this and then we can consider adding it!
    • aristo_4359

      RPM Bulk Edit Delete does not work
      Support • • aristo_4359  

      5
      0
      Votes
      5
      Posts
      15
      Views

      aristo_4359

      Thank you
    • 1 / 1