Skip to content

Conversation

@dotNomad
Copy link
Collaborator

@dotNomad dotNomad commented Jun 20, 2025

This PR adds a preference to the publisher-cves extension to show the latest ECOSYSTEM fix version from Posit Package Manager's GET /repos/{repo}/vulns API endpoint.

The ECOSYSTEM type range is described as: package ecosystem specific version range.

Previously the first fixed range version was used which resulted in a Git commit hash version for some vulnerability + package combinations.

Deployed on Dogfood here.

Fixes #195

@dotNomad dotNomad linked an issue Jun 20, 2025 that may be closed by this pull request
Copy link
Collaborator

@toph-allen toph-allen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! No comments per se.

Base automatically changed from dotnomad/193 to main June 24, 2025 18:07
@dotNomad dotNomad merged commit a63ece7 into main Jun 24, 2025
15 checks passed
@dotNomad dotNomad deleted the dotnomad/195 branch June 24, 2025 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publisher CVEs: Prefer ECOSYSTEM version fixes

3 participants