Skip to content

fix: only use the commit in api queries if the package does not have other info#349

Merged
G-Rath merged 2 commits intomainfrom
query-commit
Nov 27, 2025
Merged

fix: only use the commit in api queries if the package does not have other info#349
G-Rath merged 2 commits intomainfrom
query-commit

Conversation

@G-Rath
Copy link
Owner

@G-Rath G-Rath commented Nov 27, 2025

This matches the logic used by the vulnmatcher enricher in osv-scalibr, and generally should give more accurate results when using the api.

For example, in the Packagist ecosystem with the api we currently won't flag GHSA-3rg7-wf37-54rm because we'll send the commit through which the API doesn't match to that advisory

@G-Rath G-Rath merged commit 9893aa8 into main Nov 27, 2025
13 checks passed
@G-Rath G-Rath deleted the query-commit branch November 27, 2025 01:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant