Xueqin Cui

Results 59 comments of Xueqin Cui

Hi @LironJit, we are actively working on this! The changes to resolve Maven projects are on their way. :)

@oliverchang yes, I think so - I just started working on this!

@fviernau do you know if there is any official documentation by Swift stating the normalization rules?

LGTM - however I am not sure if we want the output in this color schema. @another-rex is there any discussion/agreement on this?

I think I reviewed it and pending changes from @G-Rath

is there any need to make a label for migration to osv-scalibr?

@G-Rath feel free to take it! I am working on another issue at the moment. :)

yes, we would like to re-design error types in v2 https://github.com/google/osv-scanner/issues/636, and this is related.

@Ais8Ooz8 thank you for your feedback! For Yarn, `devDependencies` are specified in pacakge.json and `osv-scanner` currently scans `yarn.lock` for vulnerabilities. We can report dependency groups for Yarn once we support...

Related issue to support manifest scanning: https://github.com/google/osv-scanner/issues/416