Skip to content

Do not report a package as vulnerable when the version is fixing a vulnerability #622

@pombredanne

Description

@pombredanne

On a requirements.txt file with:

cryptography==38.0.3

Run inspect_manifest then find_vulnerabilities
This package is reported as vulnerable incorrectly.

Same with:

django==3.2.16

In both cases, these are fixing vulns and these versions are not vulnerable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions