Skip to content

Granularity of go libraries #465

Answered by oliverchang
taoxinyi asked this question in Q&A
Discussion options

You must be logged in to vote

Sorry for the delayed reply here.

Per https://ossf.github.io/osv-schema/#affectedpackage-field, we do currently only track Go vulns at a module level.

My understanding this is the granularity at which package updates may be done. It doesn't make sense for instance, for someone to update github.com/argoproj/argo-events/sensors/artifacts without updating github.com/argoproj/argo-events.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by taoxinyi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants