osv.dev icon indicating copy to clipboard operation
osv.dev copied to clipboard

Provide the SEMVER "Affected ranges" in addition to the GIT "Affected ranges"

Open VinodAnandan opened this issue 3 years ago • 3 comments

https://osv.dev/vulnerability/GSD-2021-1000677

The "Affected versions" and the GIT "Affected ranges" range values are available. But providing the SEMVER "Afected ranges" too, will help with the enhanced affected component mapping. 

VinodAnandan avatar Jun 30 '22 11:06 VinodAnandan

This is technically feasible: we'd just need to correlate the introduced/fixed/limit git hashes to the closest git tags and add the additional ranges.

oliverchang avatar Jul 01 '22 05:07 oliverchang