Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Ghost" package should not be reported as a fix for vulnerability #1650

Open
TG1999 opened this issue Nov 12, 2024 · 0 comments · May be fixed by #1679
Open

"Ghost" package should not be reported as a fix for vulnerability #1650

TG1999 opened this issue Nov 12, 2024 · 0 comments · May be fixed by #1679

Comments

@TG1999
Copy link
Contributor

TG1999 commented Nov 12, 2024

https://public.vulnerablecode.io/packages/pkg:maven/log4j/[email protected]?search=maven/log4j

Reports https://public.vulnerablecode.io/packages/pkg%3Amaven/log4j/log4j%402.17.0?search=pkg:maven/log4j/[email protected] as the latest non vulnerable version of log4j. But this is a ghost package. We should not report ghost package as fix/non vulnerable for anything.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants