Armijn Hemel
Armijn Hemel
This seems to have been fixed.
This seems to work properly now.
This seems to have been fixed.
A slightly different approach would be to immediately start scanning while the file inventory process is still running. So even before the file inventory would be complete different threads would...
This one doesn't seem to have been solved.
Another example is GNU wget 1.13.2 which has actually been removed from the GNU download site.
Somewhat related are missing releases of RPM. While these have not been withdrawn it seems that they have been misplaced and can no longer be found: https://rpm.org/timeline.html (search for 'missing')
As far as I know they are sending this directly upstream so I would assume it is the same as the upstream CVE sources.
https://git.kernel.org/pub/scm/linux/security/vulns.git/log/LICENSES/cve-tou.txt
Another solution is to create "pseudo-advisories", for example, one per purl.