Hi Alana.
Thanks for your feedback. I will try it like that.
Best regards
Paddy
Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.
If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!
itadmin_9894
@itadmin_9894
Best posts made by itadmin_9894
Latest posts made by itadmin_9894
-
RE: Migrate OSS Index to PGVC
-
Migrate OSS Index to PGVC
Hi folks.
I am trying to migrate the OSS index, but I get the following error:
(500) Server Error
Could not find stored procedure 'PgvcVulnerabilities_GetMatachedVulnerabilities'.
For more information, visit the Error Log Page.Can anyone tell me where I can get this StoredProcedure?
Or is this migration not necessary if I want to update to the latest version?
THX Paddy
-
RE: How to change affected version range in Vulnerablity Assessment?
Hi @atripp ,
Thank you for your quick reply. We will try your suggested approach and migrate from OSS Index to ProGet's Vulnerability Database. We will also update our server installation.
There are other libraries with the same issue, so your statement regarding the reliability of OSS Index as a data source seems to be accurate.
Best regards
-
How to change affected version range in Vulnerablity Assessment?
Hello
Is there a way to change the range of affected package versions in a vulnerability assessment? Background: for the nuget package
bootstrap
the vulnerabilityCVE-2024-6531
is assessed for a wide range of versions, namely4.5.3, 5.2.3, 3.0.0, 3.3.7, 4.6.1, 3.3.0, 3.4.1, 5.3.3, 3.3.2, 5.3.2, 4.3.1
(see screenshot). But the versions5.3.2
and5.3.3
are not affected by this vulnerability. I would like to exclude these versions, but don't know how?We use ProGet Basic in the Version 2023.18 (Build 15).
Thank you for any feedback.