Skip to content
Discussion options

You must be logged in to vote

A component can have multiple PURLs in the sense that the PURL information becomes more specific as you read from left to right.
So pkg:golang/github.com/olekukonko/tablewriter is a valid PURL which might be useful for documenting the license, but it is of limited value for vulnerability reporting without a version.
A more specific PURL like: pkg:golang/github.com/olekukonko/[email protected]?download_url=xxxxxxxxxxxxxxxxxxxxx would be even more specific and useful.
Also - I am moving this to Discussions/Q&A which is a better home for questions

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by viveksahu26
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #502 on June 30, 2025 19:08.