Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Report only the "best" fixed version that has no vulnerabilities of its own? #1252

Open
johnmhoran opened this issue Aug 1, 2023 · 0 comments

Comments

@johnmhoran
Copy link
Member

This is related to "Report only those fixed versions that are greater than the affected version" #1228.

The question:

Do we want to display/report the most relevant/best fixed by version -- however we define "relevant"/"best" -- or do we also want to check whether that version has any vulnerabilities of its own and display/report only a vulnerability-free fixed by version? The way we currently define fixed by and organize the data in the DB, there are instances where all of the fixed by versions have vulnerabilities of their own -- none has 0 vulnerabilities.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant