You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
However, the OSV scanner doesn't detect it, because it scans dependencies, not the package itself (!). As a result, the scorecard gives it 10/10 points.
Reproduction steps
Steps to reproduce the behavior:
Run scorecard --repo=github.com/elijaa/phpmemcachedadmin
See 10 / 10 | Vulnerabilities | no vulnerabilities detected
Expected behavior
As the vulnerability is known, the score shouldn't be 10/10.
Additional context
The text was updated successfully, but these errors were encountered:
Describe the bug
Package https://github.com/elijaa/phpmemcachedadmin has disclosed a vulnerability https://osv.dev/vulnerability/CVE-2023-6026
However, the OSV scanner doesn't detect it, because it scans dependencies, not the package itself (!). As a result, the scorecard gives it 10/10 points.
Reproduction steps
Steps to reproduce the behavior:
scorecard --repo=github.com/elijaa/phpmemcachedadmin
10 / 10 | Vulnerabilities | no vulnerabilities detected
Expected behavior
As the vulnerability is known, the score shouldn't be 10/10.
Additional context
The text was updated successfully, but these errors were encountered: