-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support for non-rubygems vulnerabilities #184
Comments
I assume you're asking about checking the version of Ruby itself? That is not supported currently, mainly because afaik neither the osv.dev or GitHub advisory databases contain entries for Ruby - in terms of parsing, it would be trivial to have the |
yeah, those exist but are not actually in the database since they're marked as unreviewed - that's because the osv spec doesn't have a way of representing things like "ruby the language/sdk" so the advisory itself has no
|
I tried to review them but they do not have a required "ecosystem" value for non-rubygems. Go I have 11 GHSA "rubygems" PRs approved or merged in the last few weeks. |
In that case those advisories will be reported by |
Also found a few GHSA adversaries that were just ruby application code and pointed to a specific repo to demo it. |
Duplicated issue on osv-schema repo: ossf/osv-schema#123 |
Move this issue to osv-schecma repo: ossf/osv-schema#123 |
Appears that you get rubygem vulnerabilities by way of GHSA database feed.
Do you have support for the rubies (ruby-lang.org, jruby.org, mruby.org) languages?
Thanks.
The text was updated successfully, but these errors were encountered: