Skip to content

combine-to-osv: withdraw rejected CVEs #2147

Description

@andrewpollock

Describe the bug
While creating #2146 (off the back of #2129) it occurred to me that combine-to-osv doesn't mark rejected CVEs as withdrawn when converting them to OSV records, and I think they should be.

Expected behaviour
Rejected CVEs expressed as OSV records should be marked as withdrawn.

Screenshots
https://api.osv.dev/v1/vulns/CVE-2024-31745 is the example.

Metadata

Metadata

Assignees

Labels

backlogImportant but currently unprioritizeddata qualityIssues with data qualitygood first issueGood for newcomers

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions