Skip to content

Commit d695d97

Browse files
committed
Do not report ghost packages as fix for vulnerabilities in APIv2
Signed-off-by: Keshav Priyadarshi <[email protected]>
1 parent a5a5845 commit d695d97

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

vulnerabilities/api_v2.py

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -198,6 +198,9 @@ def get_affected_by_vulnerabilities(self, obj):
198198
return [vuln.vulnerability_id for vuln in obj.affected_by_vulnerabilities.all()]
199199

200200
def get_fixing_vulnerabilities(self, obj):
201+
# Ghost package should not fix any vulnerability.
202+
if obj.is_ghost:
203+
return []
201204
return [vuln.vulnerability_id for vuln in obj.fixing_vulnerabilities.all()]
202205

203206

0 commit comments

Comments
 (0)