Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable package has score 10/10 in Vulnerabilities #3946

Open
jorgsowa opened this issue Mar 13, 2024 · 1 comment
Open

Vulnerable package has score 10/10 in Vulnerabilities #3946

jorgsowa opened this issue Mar 13, 2024 · 1 comment
Labels
check/Vulnerabilities kind/bug Something isn't working kind/enhancement New feature or request

Comments

@jorgsowa
Copy link

Describe the bug
Package https://github.com/elijaa/phpmemcachedadmin has disclosed a vulnerability https://osv.dev/vulnerability/CVE-2023-6026

However, the OSV scanner doesn't detect it, because it scans dependencies, not the package itself (!). As a result, the scorecard gives it 10/10 points.

Reproduction steps
Steps to reproduce the behavior:

  1. Run scorecard --repo=github.com/elijaa/phpmemcachedadmin
  2. See 10 / 10 | Vulnerabilities | no vulnerabilities detected

Expected behavior
As the vulnerability is known, the score shouldn't be 10/10.

Additional context

@jorgsowa jorgsowa added the kind/bug Something isn't working label Mar 13, 2024
@spencerschrock
Copy link
Contributor

Yeah, I agree we aren't finding vulns in the current project. (See related comment google/osv-scanner#416 (comment))

I was curious if we did anything differently before the use of osv-scanner (#2509), and it seems like the answer is no

Currently the vulnerability check only checks if the HEAD commit hash has any vulnerability specified in OSV.dev

The commit hash check is still being done

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
check/Vulnerabilities kind/bug Something isn't working kind/enhancement New feature or request
Projects
Status: No status
Development

No branches or pull requests

2 participants