Does disabling 'OSS Index analyzer' breake the analysis for components like golang.org/x/crypto #5523
Unanswered
whiteninja76
asked this question in
Q&A
Replies: 1 comment
-
|
NVD only provides mapping to cpe-strings. Your components probably only have a PURL. OSS Index is thus used to map from PURL to CVEs. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi, re recently turned of teh OSS Index analyzer as its now needs a api token . which is just abit of extra config i havent sorted out yet.
I have a sbom that we upload for a project about 2 months ago thats marked the package golang.org/x/crypto as high. I have recently reload the sbom with the same details in it but a new project version number. expecting it to highlight the same findings.
ITs not showing any isssues with the sbom even thou i know its a high ...
In short
For the type of component/package
golang.org/x/cryptodo i have to have OSS Index analyzer enabled and configure for it to hightlight that its a vunerability ( the standard nvd source is still enabled)Beta Was this translation helpful? Give feedback.
All reactions