Open
Description
The current README is confusing in particular the list of supported ecosystems. We got the following comment on a PR mentioning that Go Std lib vulnerabilities are not part of the supported ecosystems.
That is highly confusing if you look at the list of supported ecosystems:
Our supported ecosystems are:
Composer (registry: https://packagist.org/)
Erlang (registry: https://hex.pm/)
GitHub Actions (registry: https://github.com/marketplace?type=actions)
**Go (registry: https://pkg.go.dev/)**
Go is present and the Standard Library is part of that registry https://pkg.go.dev/std
too.
Could you be more explicit and mention that the Standard Library is not supported ?
I also have a question, if the Go Std Library is not supported. Why does the Github advisory database accept these vulnerabilities in a first place ?
Metadata
Metadata
Assignees
Labels
No labels