-
Notifications
You must be signed in to change notification settings - Fork 225
Closed as not planned
Labels
data qualityIssues with data qualityIssues with data quality
Description
Examples:
ngx-toastr
: GH advisory affected versions>= 19.0.1, <= 19.0.2 vs OSV.dev affected all versions@ctrl/tinycolor
: GH advisory affected versions >= 4.1.1, <= 4.1.2 vs OSV.dev affected all versions@ctrl/deluge
: GH advisory affected versions >= 7.2.1, <= 7.2.2 vs OSV.dev affected all versions
Describe the data quality issue observed
There is a discrepancy with the data ingested from GH advisories, apparently at least this commit is wrongly assigning "introduced": "0"
(all versions are vulnerable) to packages where specific versions where subject to compromise.
Suggested changes to record
Fix the items, and assign the proper version / ranges
Additional context
I'm unaware if the situation is only related to this commit or if is there any others MAL records having the same problem.
Metadata
Metadata
Assignees
Labels
data qualityIssues with data qualityIssues with data quality