osv.dev icon indicating copy to clipboard operation
osv.dev copied to clipboard

`Fix available` tags are not accurate when multiple ecosystems are combined together

Open hogo6002 opened this issue 1 year ago • 1 comments

The vulnerability list page on OSV.dev currently displays a Fix available tag for vulnerabilities if at least one affected package has a fix. But when filtering vulnerabilities by a specific ecosystem, the Fix available tag remains the same even if the fix is only available for a package in a different ecosystem. It would be more accurate to display the Fix available tag based on the currently selected ecosystem filter.

Example: https://osv.dev/vulnerability/CVE-2024-43374 (no fix for Debian) image

hogo6002 avatar Aug 19 '24 06:08 hogo6002

This issue has not had any activity for 60 days and will be automatically closed in two weeks

See https://github.com/google/osv.dev/blob/master/CONTRIBUTING.md for how to contribute a PR if you're interested in helping out.

github-actions[bot] avatar Oct 18 '24 07:10 github-actions[bot]