vulnerablecode
vulnerablecode copied to clipboard
Package managers may not contain/report all versions related to a package
Example:
PyPI does not contain [email protected] (https://pypi.org/project/Django/#history), but it does exist on the official Django release website (https://docs.djangoproject.com/en/4.1/releases/1.11.19/)
also related to the "ghost" package issues in:
- https://github.com/nexB/vulnerablecode/issues/917