Skip to content

Improve parsing of osv version range #2323

@keshav-space

Description

@keshav-space

GHSA-cgjx-mwpx-47jv imported using github_osv_importer_v2 https://github.com/aboutcode-data/security-advisories/blob/99af3b1a984a55ed6b37b727fb0ada49cc0cb0d6/advisories/github_osv_importer_v2/GHSA-cgjx-mwpx-47jv.yml#L22-L28 reports this as one of the impact.

impacted_packages:
  - purl: pkg:npm/express-restify-mongoose
    affected_versions: vers:npm/<=3.0.1
    fixed_versions: vers:npm/3.1.0

here affected range should be vers:npm/>=3.0.0|<=3.0.1

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions