Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GitHub vulnerability alerts: do not limit to single version #29600

Closed
rarkins opened this issue Jun 11, 2024 · 0 comments · Fixed by #29700
Closed

GitHub vulnerability alerts: do not limit to single version #29600

rarkins opened this issue Jun 11, 2024 · 0 comments · Fixed by #29700
Assignees
Labels
core:vulnerabilities priority-3-medium Default priority, "should be done" but isn't prioritised ahead of others type:bug Bug fix of existing functionality

Comments

@rarkins
Copy link
Collaborator

rarkins commented Jun 11, 2024

Describe the proposed change(s).

Following on from #29586, we should support "greater than or equal" for non-Python ecosystems too. i.e. pick the lowest which exists.

For ecosystems which support Semver, it can be expressed as >=. For Maven it would be [version,). It's perhaps not supported for Nuget yet.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
core:vulnerabilities priority-3-medium Default priority, "should be done" but isn't prioritised ahead of others type:bug Bug fix of existing functionality
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants