Skip to content

No vulns found for pkg:github/gruntjs/[email protected], expected 3 vulns #3335

Answered by riteshnoronha
muellerst-hg asked this question in Q&A
Discussion options

You must be logged in to vote

DT doesn't have an internal mechanism to convert PURL to CPE; it relies on external services like the OSS Sonatype Analyzer and OSV for this purpose. These services need to map packages likepkg:github/gruntjs/[email protected] to cpe:2.3:a:gruntjs:grunt:1.2.1:*:*:*:*:node.js:*:* and pkg:npm/[email protected] to cpe:2.3:a:gruntjs:grunt:1.2.1:*:*:*:*:node.js:*:*.

The current mapping only associates the npm package PURL with vulnerabilities. While this aligns with the logic that most vulnerabilities discovered are filed against the package manager hosting the code, it can be confusing for end-users since, logically, they represent the same component.

AFAIK DT can't address this without independently bu…

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
4 replies
@muellerst-hg
Comment options

@riteshnoronha
Comment options

@muellerst-hg
Comment options

@riteshnoronha
Comment options

Answer selected by muellerst-hg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants