Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / google/osv-scanner issues and pull requests

#296 - Panic while parsing Pipenv lockfile

Issue - State: closed - Opened by spencerschrock over 1 year ago

#295 - Set version in source code

Pull Request - State: closed - Opened by another-rex over 1 year ago

#294 - fix: avoid infinite loops parsing Maven poms with syntax errors

Pull Request - State: closed - Opened by spencerschrock over 1 year ago - 1 comment

#292 - Prevent `.gitignore` files from interfering with tests

Pull Request - State: closed - Opened by michaelkedar over 1 year ago - 1 comment

#290 - SBOM scanning documentation improvements and more helpful error messages

Issue - State: closed - Opened by another-rex over 1 year ago
Labels: documentation

#288 - fix(deps): update osv-scanner minor

Pull Request - State: closed - Opened by renovate-bot over 1 year ago
Labels: dependencies

#286 - Alpine packaging: Tests break if other .gitignore files are present in parent directories

Issue - State: closed - Opened by kpcyrd over 1 year ago - 3 comments
Labels: bug

#284 - Adding call graph info back in

Pull Request - State: closed - Opened by hayleycd over 1 year ago

#282 - Removed call graph analysis for now.

Pull Request - State: closed - Opened by hayleycd over 1 year ago

#281 - Improve `IgnoredVulns` ergonomics

Issue - State: closed - Opened by ericcornelissen over 1 year ago - 3 comments
Labels: enhancement

#280 - chore: semantic fixture generators improvements

Pull Request - State: closed - Opened by G-Rath over 1 year ago

#278 - Update Colors for Accessibility

Pull Request - State: closed - Opened by hayleycd over 1 year ago

#275 - Remove "working doc" concept

Pull Request - State: closed - Opened by hayleycd over 1 year ago - 4 comments

#274 - All output goes to stdout when format is json

Issue - State: closed - Opened by tepentti over 1 year ago - 6 comments

#271 - Update documentation on how to scan local Debian/Ubuntu OS

Issue - State: closed - Opened by KoenDG over 1 year ago - 4 comments
Labels: documentation, stale, autoclosed

#255 - Rpmdb support

Pull Request - State: open - Opened by cmaritan over 1 year ago - 8 comments

#254 - Add RPM/Red Hat ecosystem support

Issue - State: open - Opened by cmaritan over 1 year ago - 1 comment
Labels: backlog

#253 - feat: improved error message when pom dependency version not found

Pull Request - State: closed - Opened by raboof over 1 year ago - 6 comments

#240 - Support scanning remote OS

Issue - State: closed - Opened by KoenDG over 1 year ago - 3 comments
Labels: enhancement, stale, autoclosed

#239 - Version flag returns non-specific information

Issue - State: closed - Opened by hayleycd over 1 year ago - 7 comments

#238 - User informed when new version available

Issue - State: open - Opened by hayleycd over 1 year ago - 3 comments
Labels: enhancement, backlog

#237 - Results unclear when no vulnerabilities are found.

Issue - State: closed - Opened by hayleycd over 1 year ago - 4 comments

#235 - Adding additional installation instructions

Pull Request - State: closed - Opened by hayleycd over 1 year ago

#234 - Moving Working Docs to Current

Pull Request - State: closed - Opened by hayleycd over 1 year ago

#219 - [Tracking Issue] Enrich Output Report Formats

Issue - State: closed - Opened by Dentrax over 1 year ago - 2 comments
Labels: stale, autoclosed

#216 - Add support for SARIF output

Issue - State: closed - Opened by Dentrax over 1 year ago - 20 comments
Labels: enhancement

#209 - Gitignore parsing does not respect repository boundaries

Issue - State: open - Opened by michaelkedar almost 2 years ago - 4 comments
Labels: bug, backlog

#207 - SBOM-like output

Issue - State: open - Opened by oliverchang almost 2 years ago - 2 comments
Labels: enhancement, backlog

#200 - Cleanup dependencies between pkg and internal packages

Pull Request - State: closed - Opened by dburriss almost 2 years ago - 2 comments

#199 - Move output package from /internal to /pkg

Issue - State: closed - Opened by dburriss almost 2 years ago - 3 comments

#189 - feat: support passing `io.Reader` to `lockfile` parsers

Pull Request - State: closed - Opened by G-Rath almost 2 years ago - 2 comments

#186 - feat: support diagnostics in `lockfile` parsers

Pull Request - State: closed - Opened by G-Rath almost 2 years ago - 17 comments

#183 - feat: add experimental offline mode

Pull Request - State: closed - Opened by G-Rath almost 2 years ago - 9 comments

#177 - Support additional SPDX package manager types

Issue - State: open - Opened by oliverchang almost 2 years ago - 1 comment
Labels: enhancement, backlog

#176 - Add `io.Reader` variants to `lockfile` package

Issue - State: closed - Opened by picatz almost 2 years ago - 18 comments
Labels: enhancement

#175 - Add automated benchmarks and profiling

Issue - State: open - Opened by another-rex almost 2 years ago - 1 comment
Labels: enhancement, infra, backlog

#174 - Create integration tests

Issue - State: open - Opened by another-rex almost 2 years ago - 2 comments
Labels: infra, backlog

#164 - Docker OS packages scan (for Debian and Alpine)

Pull Request - State: closed - Opened by cmaritan almost 2 years ago - 7 comments

#155 - Support CycloneDX output format

Issue - State: closed - Opened by fproulx-boostsecurity almost 2 years ago - 2 comments
Labels: enhancement, stale

#151 - Exclude Packages by Regex Value from Scan

Issue - State: open - Opened by gromhacks almost 2 years ago - 1 comment
Labels: enhancement, good first issue

#150 - Add line-numbers to the output

Issue - State: open - Opened by agmond almost 2 years ago - 5 comments
Labels: enhancement, backlog

#144 - Prettier lint md workflow

Pull Request - State: closed - Opened by wolf99 almost 2 years ago - 3 comments

#129 - Workflow for linting markdown files

Pull Request - State: closed - Opened by wolf99 almost 2 years ago - 8 comments

#128 - Alpine APK installed: support for flag check-apk-installed

Pull Request - State: closed - Opened by cmaritan almost 2 years ago - 8 comments

#126 - Goreleaser run github PR tests before releasing.

Issue - State: closed - Opened by another-rex almost 2 years ago - 2 comments
Labels: help wanted, infra

#123 - Augment output with CVSS information.

Issue - State: open - Opened by themenucha almost 2 years ago - 9 comments
Labels: enhancement, backlog

#119 - No clear error message when scanning Docker container

Issue - State: closed - Opened by vdespa almost 2 years ago - 1 comment
Labels: enhancement, backlog

#117 - Enabling the JSON report should not disable the CLI report

Issue - State: open - Opened by vdespa almost 2 years ago - 4 comments
Labels: enhancement, backlog

#114 - Bazel support

Issue - State: open - Opened by zsims almost 2 years ago - 3 comments
Labels: enhancement, backlog

#111 - Windows binary is flagged by Virustotal (Google AV)

Issue - State: closed - Opened by ckrueger1979 almost 2 years ago - 3 comments

#97 - Add exploitability information

Issue - State: open - Opened by themenucha almost 2 years ago - 1 comment
Labels: enhancement, backlog

#95 - Allow lockfile to be read from STDIN

Issue - State: open - Opened by corey-cole almost 2 years ago - 4 comments
Labels: enhancement, good first issue

#93 - No package sources found Error when scanning SBOMs

Issue - State: closed - Opened by MFaisalZaki almost 2 years ago - 16 comments
Labels: question

#91 - Transitive Dependencies

Issue - State: open - Opened by theinfosecguy almost 2 years ago - 16 comments
Labels: enhancement, backlog

#86 - Better error output for malformed inputs.

Issue - State: closed - Opened by 0-wiz-0 almost 2 years ago - 4 comments
Labels: bug

#82 - Support C/C++

Issue - State: closed - Opened by oliverchang almost 2 years ago - 7 comments
Labels: enhancement

#81 - Support local DBs

Issue - State: closed - Opened by oliverchang almost 2 years ago - 9 comments
Labels: enhancement

#64 - Improve container scanning.

Issue - State: open - Opened by oliverchang almost 2 years ago - 3 comments
Labels: enhancement, priority

#62 - JUnit report

Issue - State: open - Opened by EBCEEB almost 2 years ago - 1 comment
Labels: help wanted, backlog

#60 - support pre-commit

Issue - State: closed - Opened by Niccolum almost 2 years ago - 2 comments
Labels: enhancement, good first issue

#57 - Build GitHub actions for running osv-scanner

Issue - State: closed - Opened by oliverchang about 2 years ago - 7 comments
Labels: enhancement

#55 - Implement others ways of installation

Issue - State: open - Opened by jwillker almost 2 years ago - 7 comments
Labels: backlog

#51 - Scan nuget

Issue - State: closed - Opened by vbjay almost 2 years ago - 12 comments
Labels: enhancement

#35 - Better support for transitive deps in Maven/Java (pom.xml)

Issue - State: closed - Opened by oliverchang almost 2 years ago - 13 comments
Labels: enhancement, priority

#34 - Better support for transitive deps in Python (requirements.txt)

Issue - State: open - Opened by oliverchang almost 2 years ago - 5 comments
Labels: enhancement, backlog

#31 - fix: include `replace` directives in `go.mod`

Pull Request - State: closed - Opened by G-Rath almost 2 years ago - 3 comments

#19 - Generating VEX statements

Issue - State: open - Opened by another-rex almost 2 years ago - 3 comments
Labels: enhancement, backlog

#12 - osv-scanner: Suggest fixes

Issue - State: closed - Opened by oliverchang about 2 years ago - 2 comments
Labels: enhancement, stale

#11 - osv-scanner: Callgraph analysis to help prioritize matched vulnerabilities

Issue - State: closed - Opened by oliverchang about 2 years ago - 1 comment
Labels: enhancement

#10 - osv-scanner: integrate vulncheck

Issue - State: closed - Opened by oliverchang about 2 years ago - 3 comments
Labels: enhancement

#9 - osv-scanner: Scan .jar files

Issue - State: open - Opened by oliverchang about 2 years ago - 3 comments
Labels: enhancement, backlog

#6 - Dependency Dashboard

Issue - State: open - Opened by forking-renovate[bot] almost 2 years ago