-
Notifications
You must be signed in to change notification settings - Fork 12
Incorrect golang version handling #129
Comments
Edit: removed incorrect information to prevent any future confusion |
@ndonewar Thanks for answer! BTW, This package should not be vulnerable, it has been fixed in 1.5.0:
|
@patryk4815 My apologies, I started digging into this one more and realized I gave you incorrect information (removed above to prevent future confusion). Here's the correct info: Go components in OSS Index should be referenced without the As you noted, 1.5.0 should not have the vulnerability, and that is what is shown: And lower versions (e.g., 1.4.0) should have the vulnerability, and they do: Sorry for any inconvenience this caused! |
The issue where some Go component pages were incorrectly listing versions with For example, versions here no longer show a |
If it is fixed we can close ticket :) |
Vulnerability URL
Provide the URL to the OSS Index vulnerability. eg:
Description
What is difference between v1.5.0 and 1.5.0 in golang repos?
The text was updated successfully, but these errors were encountered: