From 68e641b315d00908b56ffec98011baf7d889df51 Mon Sep 17 00:00:00 2001 From: osv-robot Date: Tue, 26 May 2026 21:27:38 +0000 Subject: [PATCH] test: update cassettes --- .../fix/__snapshots__/command_test.snap | 88 +-- .../image/__snapshots__/command_test.snap | 28 +- .../cassettes/TestCommand_OCIImage.yaml | 288 ++++--- .../TestCommand_OCIImage_JSONFormat.yaml | 158 ++-- .../source/__snapshots__/command_test.snap | 44 +- .../testdata/cassettes/TestCommand.yaml | 62 +- .../cassettes/TestCommand_CommitSupport.yaml | 4 +- .../TestCommand_Config_UnusedIgnores.yaml | 52 +- .../cassettes/TestCommand_GithubActions.yaml | 2 +- .../cassettes/TestCommand_Transitive.yaml | 737 +----------------- 10 files changed, 451 insertions(+), 1012 deletions(-) diff --git a/cmd/osv-scanner/fix/__snapshots__/command_test.snap b/cmd/osv-scanner/fix/__snapshots__/command_test.snap index c3685face1f..d5e34065317 100755 --- a/cmd/osv-scanner/fix/__snapshots__/command_test.snap +++ b/cmd/osv-scanner/fix/__snapshots__/command_test.snap @@ -5263,7 +5263,7 @@ Guided remediation (the fix command) can be risky when run on untrusted projects Found 16 vulnerabilities matching the filter Can fix 8/16 matching vulnerabilities by changing 5 dependencies UPGRADED-PACKAGE: minimatch,3.1.2,3.1.5 -UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.14 +UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.15 UPGRADED-PACKAGE: ajv,6.12.6,6.15.0 UPGRADED-PACKAGE: concat-stream,1.5.0,1.6.1 UPGRADED-PACKAGE: hosted-git-info,2.1.4,2.8.9 @@ -5379,12 +5379,12 @@ UNFIXABLE-VULNS: 8 } }, "node_modules/brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "dependencies": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "node_modules/caseless": { @@ -6299,12 +6299,12 @@ UNFIXABLE-VULNS: 8 } }, "brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "requires": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "caseless": { @@ -7205,7 +7205,7 @@ UNFIXABLE-VULNS: 8 { "name": "brace-expansion", "versionFrom": "1.1.11", - "versionTo": "1.1.14", + "versionTo": "1.1.15", "transitive": true } ], @@ -7405,12 +7405,12 @@ Guided remediation (the fix command) can be risky when run on untrusted projects } }, "node_modules/brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "dependencies": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "node_modules/caseless": { @@ -8325,12 +8325,12 @@ Guided remediation (the fix command) can be risky when run on untrusted projects } }, "brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "requires": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "caseless": { @@ -9631,7 +9631,7 @@ Guided remediation (the fix command) can be risky when run on untrusted projects Found 16 vulnerabilities matching the filter Can fix 8/16 matching vulnerabilities by changing 5 dependencies UPGRADED-PACKAGE: minimatch,3.1.2,3.1.5 -UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.14 +UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.15 UPGRADED-PACKAGE: ajv,6.12.6,6.15.0 UPGRADED-PACKAGE: concat-stream,1.5.0,1.6.1 UPGRADED-PACKAGE: hosted-git-info,2.1.4,2.8.9 @@ -9747,12 +9747,12 @@ UNFIXABLE-VULNS: 8 } }, "node_modules/brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "dependencies": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "node_modules/caseless": { @@ -10667,12 +10667,12 @@ UNFIXABLE-VULNS: 8 } }, "brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "requires": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "caseless": { @@ -11450,7 +11450,7 @@ Guided remediation (the fix command) can be risky when run on untrusted projects Found 16 vulnerabilities matching the filter Can fix 8/16 matching vulnerabilities by changing 5 dependencies UPGRADED-PACKAGE: minimatch,3.1.2,3.1.5 -UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.14 +UPGRADED-PACKAGE: brace-expansion,1.1.11,1.1.15 UPGRADED-PACKAGE: ajv,6.12.6,6.15.0 UPGRADED-PACKAGE: concat-stream,1.5.0,1.6.1 UPGRADED-PACKAGE: hosted-git-info,2.1.4,2.8.9 @@ -11566,12 +11566,12 @@ UNFIXABLE-VULNS: 8 } }, "node_modules/brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "dependencies": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "node_modules/caseless": { @@ -12486,12 +12486,12 @@ UNFIXABLE-VULNS: 8 } }, "brace-expansion": { - "version": "1.1.14", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.14.tgz", - "integrity": "sha512-MWPGfDxnyzKU7rNOW9SP/c50vi3xrmrua/+6hfPbCS2ABNWfx24vPidzvC7krjU/RTo235sV776ymlsMtGKj8g==", + "version": "1.1.15", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", + "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", "requires": { - "concat-map": "0.0.1", - "balanced-match": "^1.0.0" + "balanced-match": "^1.0.0", + "concat-map": "0.0.1" } }, "caseless": { diff --git a/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap b/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap index e692b1c23de..7116cb51255 100755 --- a/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap +++ b/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap @@ -444,7 +444,7 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" Container Scanning Result (Ubuntu 22.04.5 LTS) (Based on "library/ubuntu" image): -Total 25 packages affected by 69 known vulnerabilities (6 Critical, 19 High, 37 Medium, 5 Low, 2 Unknown) from 1 ecosystem. +Total 25 packages affected by 73 known vulnerabilities (6 Critical, 19 High, 37 Medium, 5 Low, 6 Unknown) from 1 ecosystem. 29 vulnerabilities can be fixed. @@ -470,7 +470,7 @@ Ubuntu:22.04 | openssl | 3.0.2-0ubuntu1.18 | Partial fixes Available | 6 | libssl3 | # 4 Layer | library/ubuntu | | pam | 1.4.0-11ubuntu2.5 | Partial fixes Available | 2 | libpam-modules... (4) | # 4 Layer | library/ubuntu | | pcre2 | 10.39-3ubuntu0.1 | No fix available | 1 | libpcre2-8-0 | # 4 Layer | library/ubuntu | -| perl | 5.34.0-3ubuntu1.3 | Partial fixes Available | 3 | perl-base | # 4 Layer | library/ubuntu | +| perl | 5.34.0-3ubuntu1.3 | Partial fixes Available | 7 | perl-base | # 4 Layer | library/ubuntu | | sed | 4.8-1ubuntu2 | Fix Available | 1 | sed | # 4 Layer | library/ubuntu | | shadow | 1:4.8.1-2ubuntu2.2 | No fix available | 2 | login, passwd | # 4 Layer | library/ubuntu | | systemd | 249.11-0ubuntu3.12 | Partial fixes Available | 9 | libsystemd0... (2) | # 4 Layer | library/ubuntu | @@ -496,7 +496,7 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" Container Scanning Result (Ubuntu 22.04.5 LTS) (Based on "library/ubuntu" image): -Total 25 packages affected by 69 known vulnerabilities (6 Critical, 19 High, 37 Medium, 5 Low, 2 Unknown) from 1 ecosystem. +Total 25 packages affected by 73 known vulnerabilities (6 Critical, 19 High, 37 Medium, 5 Low, 6 Unknown) from 1 ecosystem. 29 vulnerabilities can be fixed. @@ -522,7 +522,7 @@ Ubuntu:22.04 | openssl | 3.0.2-0ubuntu1.18 | Partial fixes Available | 6 | libssl3 | # 4 Layer | library/ubuntu | | pam | 1.4.0-11ubuntu2.5 | Partial fixes Available | 2 | libpam-modules... (4) | # 4 Layer | library/ubuntu | | pcre2 | 10.39-3ubuntu0.1 | No fix available | 1 | libpcre2-8-0 | # 4 Layer | library/ubuntu | -| perl | 5.34.0-3ubuntu1.3 | Partial fixes Available | 3 | perl-base | # 4 Layer | library/ubuntu | +| perl | 5.34.0-3ubuntu1.3 | Partial fixes Available | 7 | perl-base | # 4 Layer | library/ubuntu | | sed | 4.8-1ubuntu2 | Fix Available | 1 | sed | # 4 Layer | library/ubuntu | | shadow | 1:4.8.1-2ubuntu2.2 | No fix available | 2 | login, passwd | # 4 Layer | library/ubuntu | | systemd | 249.11-0ubuntu3.12 | Partial fixes Available | 9 | libsystemd0... (2) | # 4 Layer | library/ubuntu | @@ -567,7 +567,7 @@ Scanning local image tarball "./testdata/test-ubuntu-with-packages.tar" Container Scanning Result (Ubuntu 22.04.5 LTS) (Based on "library/ubuntu" image): -Total 25 packages affected by 69 known vulnerabilities (6 Critical, 19 High, 37 Medium, 5 Low, 2 Unknown) from 1 ecosystem. +Total 25 packages affected by 73 known vulnerabilities (6 Critical, 19 High, 37 Medium, 5 Low, 6 Unknown) from 1 ecosystem. 29 vulnerabilities can be fixed. @@ -593,7 +593,7 @@ Ubuntu:22.04 | openssl | 3.0.2-0ubuntu1.18 | Partial fixes Available | 6 | libssl3 | # 4 Layer | library/ubuntu | | pam | 1.4.0-11ubuntu2.5 | Partial fixes Available | 2 | libpam-modules... (4) | # 4 Layer | library/ubuntu | | pcre2 | 10.39-3ubuntu0.1 | No fix available | 1 | libpcre2-8-0 | # 4 Layer | library/ubuntu | -| perl | 5.34.0-3ubuntu1.3 | Partial fixes Available | 3 | perl-base | # 4 Layer | library/ubuntu | +| perl | 5.34.0-3ubuntu1.3 | Partial fixes Available | 7 | perl-base | # 4 Layer | library/ubuntu | | sed | 4.8-1ubuntu2 | Fix Available | 1 | sed | # 4 Layer | library/ubuntu | | shadow | 1:4.8.1-2ubuntu2.2 | No fix available | 2 | login, passwd | # 4 Layer | library/ubuntu | | systemd | 249.11-0ubuntu3.12 | Partial fixes Available | 9 | libsystemd0... (2) | # 4 Layer | library/ubuntu | @@ -4386,14 +4386,18 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "index": 4 } }, - "groups": 4, + "groups": 8, "vulnerabilities": [ "USN-7434-1", "USN-7678-1", "UBUNTU-CVE-2023-31486", "UBUNTU-CVE-2023-47039", "UBUNTU-CVE-2024-56406", - "UBUNTU-CVE-2025-40909" + "UBUNTU-CVE-2025-40909", + "UBUNTU-CVE-2026-42496", + "UBUNTU-CVE-2026-42497", + "UBUNTU-CVE-2026-8376", + "UBUNTU-CVE-2026-9538" ] }, { @@ -5475,14 +5479,18 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "index": 4 } }, - "groups": 4, + "groups": 8, "vulnerabilities": [ "USN-7434-1", "USN-7678-1", "UBUNTU-CVE-2023-31486", "UBUNTU-CVE-2023-47039", "UBUNTU-CVE-2024-56406", - "UBUNTU-CVE-2025-40909" + "UBUNTU-CVE-2025-40909", + "UBUNTU-CVE-2026-42496", + "UBUNTU-CVE-2026-42497", + "UBUNTU-CVE-2026-8376", + "UBUNTU-CVE-2026-9538" ] }, { diff --git a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml index 68dcc486e6b..cac59a0ceff 100644 --- a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml +++ b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml @@ -2324,7 +2324,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 17153 + content_length: 17439 body: | { "results": [ @@ -2477,7 +2477,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -2553,7 +2553,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -2721,7 +2721,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-5260", - "modified": "2026-05-11T10:47:15.892810Z" + "modified": "2026-05-26T19:29:25.979351Z" }, { "id": "USN-7281-1", @@ -2737,7 +2737,7 @@ interactions: }, { "id": "USN-8284-1", - "modified": "2026-05-20T22:17:49.967138Z" + "modified": "2026-05-26T19:44:20.839441Z" } ] }, @@ -3460,6 +3460,22 @@ interactions: "id": "UBUNTU-CVE-2025-40909", "modified": "2026-04-22T16:02:28.067448Z" }, + { + "id": "UBUNTU-CVE-2026-42496", + "modified": "2026-05-26T14:30:12.532401Z" + }, + { + "id": "UBUNTU-CVE-2026-42497", + "modified": "2026-05-26T14:30:12.353438Z" + }, + { + "id": "UBUNTU-CVE-2026-8376", + "modified": "2026-05-22T20:30:09.323011Z" + }, + { + "id": "UBUNTU-CVE-2026-9538", + "modified": "2026-05-26T14:30:16.719399Z" + }, { "id": "USN-7434-1", "modified": "2026-04-22T10:56:55.320362Z" @@ -3523,7 +3539,7 @@ interactions: } headers: Content-Length: - - "17153" + - "17439" Content-Type: - application/json status: 200 OK @@ -4258,7 +4274,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 17153 + content_length: 17439 body: | { "results": [ @@ -4411,7 +4427,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -4487,7 +4503,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -4655,7 +4671,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-5260", - "modified": "2026-05-11T10:47:15.892810Z" + "modified": "2026-05-26T19:29:25.979351Z" }, { "id": "USN-7281-1", @@ -4671,7 +4687,7 @@ interactions: }, { "id": "USN-8284-1", - "modified": "2026-05-20T22:17:49.967138Z" + "modified": "2026-05-26T19:44:20.839441Z" } ] }, @@ -5394,6 +5410,22 @@ interactions: "id": "UBUNTU-CVE-2025-40909", "modified": "2026-04-22T16:02:28.067448Z" }, + { + "id": "UBUNTU-CVE-2026-42496", + "modified": "2026-05-26T14:30:12.532401Z" + }, + { + "id": "UBUNTU-CVE-2026-42497", + "modified": "2026-05-26T14:30:12.353438Z" + }, + { + "id": "UBUNTU-CVE-2026-8376", + "modified": "2026-05-22T20:30:09.323011Z" + }, + { + "id": "UBUNTU-CVE-2026-9538", + "modified": "2026-05-26T14:30:16.719399Z" + }, { "id": "USN-7434-1", "modified": "2026-04-22T10:56:55.320362Z" @@ -5457,7 +5489,7 @@ interactions: } headers: Content-Length: - - "17153" + - "17439" Content-Type: - application/json status: 200 OK @@ -6206,7 +6238,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 23286 + content_length: 23572 body: | { "results": [ @@ -6566,7 +6598,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -6574,7 +6606,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -6582,7 +6614,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -6590,11 +6622,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -6602,7 +6634,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -6614,7 +6646,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -6626,7 +6658,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -6634,11 +6666,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -6760,7 +6792,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -6836,7 +6868,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -7004,7 +7036,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-5260", - "modified": "2026-05-11T10:47:15.892810Z" + "modified": "2026-05-26T19:29:25.979351Z" }, { "id": "USN-7281-1", @@ -7020,7 +7052,7 @@ interactions: }, { "id": "USN-8284-1", - "modified": "2026-05-20T22:17:49.967138Z" + "modified": "2026-05-26T19:44:20.839441Z" } ] }, @@ -7743,6 +7775,22 @@ interactions: "id": "UBUNTU-CVE-2025-40909", "modified": "2026-04-22T16:02:28.067448Z" }, + { + "id": "UBUNTU-CVE-2026-42496", + "modified": "2026-05-26T14:30:12.532401Z" + }, + { + "id": "UBUNTU-CVE-2026-42497", + "modified": "2026-05-26T14:30:12.353438Z" + }, + { + "id": "UBUNTU-CVE-2026-8376", + "modified": "2026-05-22T20:30:09.323011Z" + }, + { + "id": "UBUNTU-CVE-2026-9538", + "modified": "2026-05-26T14:30:16.719399Z" + }, { "id": "USN-7434-1", "modified": "2026-04-22T10:56:55.320362Z" @@ -7806,7 +7854,7 @@ interactions: } headers: Content-Length: - - "23286" + - "23572" Content-Type: - application/json status: 200 OK @@ -10177,7 +10225,7 @@ interactions: "vulns": [ { "id": "GHSA-337m-mw94-2v6g", - "modified": "2026-05-20T15:48:07.587060Z" + "modified": "2026-05-21T06:29:17.115065Z" }, { "id": "GHSA-9w38-p64v-xpmv", @@ -12383,7 +12431,7 @@ interactions: "vulns": [ { "id": "GHSA-65pc-fj4g-8rjx", - "modified": "2026-05-19T14:45:16.378872Z" + "modified": "2026-05-21T01:29:26.777151Z" }, { "id": "GHSA-jjg7-2v4v-x38h", @@ -13226,7 +13274,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -13234,7 +13282,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -13242,7 +13290,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -13250,11 +13298,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -13262,7 +13310,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -13274,7 +13322,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -13286,7 +13334,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -13294,11 +13342,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -13418,7 +13466,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -13426,7 +13474,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -13434,7 +13482,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -13442,11 +13490,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -13454,7 +13502,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -13466,7 +13514,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -13478,7 +13526,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -13486,11 +13534,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -13610,7 +13658,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -13618,7 +13666,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -13626,7 +13674,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -13634,11 +13682,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -13646,7 +13694,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -13658,7 +13706,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -13670,7 +13718,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -13678,11 +13726,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -13802,7 +13850,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -13810,7 +13858,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -13818,7 +13866,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -13826,11 +13874,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -13838,7 +13886,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -13850,7 +13898,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -13862,7 +13910,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -13870,11 +13918,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -13994,7 +14042,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -14002,7 +14050,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -14010,7 +14058,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -14018,11 +14066,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -14030,7 +14078,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -14042,7 +14090,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -14054,7 +14102,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -14062,11 +14110,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -14186,7 +14234,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -14194,7 +14242,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -14202,7 +14250,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -14210,11 +14258,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -14222,7 +14270,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -14234,7 +14282,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -14246,7 +14294,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -14254,11 +14302,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -15450,7 +15498,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -15462,7 +15510,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -15474,7 +15522,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -15482,11 +15530,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -15522,7 +15570,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -15534,7 +15582,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -15546,7 +15594,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -15554,11 +15602,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -15594,7 +15642,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -15606,7 +15654,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -15618,7 +15666,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -15626,11 +15674,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -15666,7 +15714,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -15678,7 +15726,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -15690,7 +15738,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -15698,11 +15746,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -15738,7 +15786,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -15750,7 +15798,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -15762,7 +15810,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -15770,11 +15818,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -15810,7 +15858,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -15822,7 +15870,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -15834,7 +15882,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -15842,11 +15890,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", diff --git a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml index 4944ec0bc8e..e7785807197 100644 --- a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml +++ b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml @@ -929,7 +929,7 @@ interactions: "vulns": [ { "id": "GHSA-65pc-fj4g-8rjx", - "modified": "2026-05-19T14:45:16.378872Z" + "modified": "2026-05-21T01:29:26.777151Z" }, { "id": "GHSA-jjg7-2v4v-x38h", @@ -2314,7 +2314,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -2322,7 +2322,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -2330,7 +2330,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -2338,11 +2338,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -2350,7 +2350,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -2362,7 +2362,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -2374,7 +2374,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -2382,11 +2382,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -3263,7 +3263,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -3275,7 +3275,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -3287,7 +3287,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -3295,11 +3295,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -3335,7 +3335,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -3347,7 +3347,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -3359,7 +3359,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -3367,11 +3367,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -3407,7 +3407,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -3419,7 +3419,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -3431,7 +3431,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -3439,11 +3439,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -3479,7 +3479,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -3491,7 +3491,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -3503,7 +3503,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -3511,11 +3511,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -3551,7 +3551,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -3563,7 +3563,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -3575,7 +3575,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -3583,11 +3583,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -3623,7 +3623,7 @@ interactions: "vulns": [ { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -3635,7 +3635,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -3647,7 +3647,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -3655,11 +3655,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -4823,7 +4823,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 17153 + content_length: 17439 body: | { "results": [ @@ -4976,7 +4976,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -5052,7 +5052,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -5220,7 +5220,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-5260", - "modified": "2026-05-11T10:47:15.892810Z" + "modified": "2026-05-26T19:29:25.979351Z" }, { "id": "USN-7281-1", @@ -5236,7 +5236,7 @@ interactions: }, { "id": "USN-8284-1", - "modified": "2026-05-20T22:17:49.967138Z" + "modified": "2026-05-26T19:44:20.839441Z" } ] }, @@ -5959,6 +5959,22 @@ interactions: "id": "UBUNTU-CVE-2025-40909", "modified": "2026-04-22T16:02:28.067448Z" }, + { + "id": "UBUNTU-CVE-2026-42496", + "modified": "2026-05-26T14:30:12.532401Z" + }, + { + "id": "UBUNTU-CVE-2026-42497", + "modified": "2026-05-26T14:30:12.353438Z" + }, + { + "id": "UBUNTU-CVE-2026-8376", + "modified": "2026-05-22T20:30:09.323011Z" + }, + { + "id": "UBUNTU-CVE-2026-9538", + "modified": "2026-05-26T14:30:16.719399Z" + }, { "id": "USN-7434-1", "modified": "2026-04-22T10:56:55.320362Z" @@ -6022,7 +6038,7 @@ interactions: } headers: Content-Length: - - "17153" + - "17439" Content-Type: - application/json status: 200 OK @@ -6771,7 +6787,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 23286 + content_length: 23572 body: | { "results": [ @@ -7131,7 +7147,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -7139,7 +7155,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -7147,7 +7163,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -7155,11 +7171,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4403", @@ -7167,7 +7183,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -7179,7 +7195,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -7191,7 +7207,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -7199,11 +7215,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -7325,7 +7341,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -7401,7 +7417,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-4438", - "modified": "2026-04-27T18:57:18.006868Z" + "modified": "2026-05-26T19:29:26.030423Z" }, { "id": "UBUNTU-CVE-2026-5435", @@ -7569,7 +7585,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-5260", - "modified": "2026-05-11T10:47:15.892810Z" + "modified": "2026-05-26T19:29:25.979351Z" }, { "id": "USN-7281-1", @@ -7585,7 +7601,7 @@ interactions: }, { "id": "USN-8284-1", - "modified": "2026-05-20T22:17:49.967138Z" + "modified": "2026-05-26T19:44:20.839441Z" } ] }, @@ -8308,6 +8324,22 @@ interactions: "id": "UBUNTU-CVE-2025-40909", "modified": "2026-04-22T16:02:28.067448Z" }, + { + "id": "UBUNTU-CVE-2026-42496", + "modified": "2026-05-26T14:30:12.532401Z" + }, + { + "id": "UBUNTU-CVE-2026-42497", + "modified": "2026-05-26T14:30:12.353438Z" + }, + { + "id": "UBUNTU-CVE-2026-8376", + "modified": "2026-05-22T20:30:09.323011Z" + }, + { + "id": "UBUNTU-CVE-2026-9538", + "modified": "2026-05-26T14:30:16.719399Z" + }, { "id": "USN-7434-1", "modified": "2026-04-22T10:56:55.320362Z" @@ -8371,7 +8403,7 @@ interactions: } headers: Content-Length: - - "23286" + - "23572" Content-Type: - application/json status: 200 OK diff --git a/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap b/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap index d53646fe1cb..b8b241c2b8d 100755 --- a/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap +++ b/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap @@ -1129,8 +1129,8 @@ Scanned /testdata/sbom-insecure/postgres-stretch.cdx.xml file and found Scanned /testdata/sbom-insecure/with-duplicates.cdx.xml file and found 17 packages Filtered 10 local/unscannable package/s from the scan. -Total 27 packages affected by 200 known vulnerabilities (22 Critical, 86 High, 65 Medium, 4 Low, 23 Unknown) from 4 ecosystems. -11 vulnerabilities can be fixed. +Total 27 packages affected by 205 known vulnerabilities (22 Critical, 86 High, 65 Medium, 4 Low, 28 Unknown) from 4 ecosystems. +12 vulnerabilities can be fixed. +---------------------------------------+------+-----------+--------------------------------+------------------------------------+-----------------------------------+---------------------------------------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | @@ -1157,6 +1157,7 @@ Total 27 packages affected by 200 known vulnerabilities (22 Critical, 86 High, 6 | https://osv.dev/GHSA-cgrx-mc8f-2prm | | | | | | | | https://osv.dev/GO-2022-0493 | 5.3 | Go | golang.org/x/sys | v0.0.0-20210817142637-7d9622a276b7 | 0.0.0-20220412211240-33da011f77ad | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/GHSA-p782-xgp4-8hr8 | | | | | | | +| https://osv.dev/GO-2026-5024 | | Go | golang.org/x/sys | v0.0.0-20210817142637-7d9622a276b7 | 0.44.0 | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/ALPINE-CVE-2022-37434 | 9.8 | Alpine | zlib | 1.2.12-r1 | -- | testdata/sbom-insecure/alpine-zlib-16.cdx.json:lib/apk/db/installed | | https://osv.dev/ALPINE-CVE-2026-22184 | 7.8 | Alpine | zlib | 1.2.12-r1 | -- | testdata/sbom-insecure/alpine-zlib-16.cdx.json:lib/apk/db/installed | | https://osv.dev/ALPINE-CVE-2026-27171 | 5.5 | Alpine | zlib | 1.2.12-r1 | -- | testdata/sbom-insecure/alpine-zlib-16.cdx.json:lib/apk/db/installed | @@ -1329,6 +1330,10 @@ Total 27 packages affected by 200 known vulnerabilities (22 Critical, 86 High, 6 | https://osv.dev/DEBIAN-CVE-2021-36770 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2023-47038 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-40909 | 5.9 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42496 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42497 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-8376 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-9538 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5135-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3072-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3189-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -1874,7 +1879,7 @@ Scanned /testdata/locks-requirements/the_requirements_for_test.txt file Scanned /testdata/locks-requirements/unresolvable-requirements.txt file and found 3 packages Total 12 packages affected by 52 known vulnerabilities (5 Critical, 20 High, 22 Medium, 4 Low, 1 Unknown) from 1 ecosystem. -51 vulnerabilities can be fixed. +50 vulnerabilities can be fixed. +-------------------------------------+------+-----------+------------+---------+---------------+-----------------------------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | @@ -1942,10 +1947,11 @@ Total 12 packages affected by 52 known vulnerabilities (5 Critical, 20 High, 22 | https://osv.dev/GHSA-68rp-wp8r-4726 | 2.3 | PyPI | flask | 1.0.0 | 3.1.3 | testdata/locks-requirements/unresolvable-requirements.txt | | https://osv.dev/PYSEC-2020-43 | 8.7 | PyPI | flask-cors | 1.0.0 | 3.0.9 | testdata/locks-requirements/unresolvable-requirements.txt | | https://osv.dev/GHSA-xc3p-ff3m-f46v | | | | | | | +| https://osv.dev/PYSEC-2024-260 | 8.7 | PyPI | flask-cors | 1.0.0 | -- | testdata/locks-requirements/unresolvable-requirements.txt | +| https://osv.dev/PYSEC-2024-71 | | | | | | | +| https://osv.dev/GHSA-hxwh-jpp2-84pm | | | | | | | | https://osv.dev/PYSEC-2024-271 | 5.3 | PyPI | flask-cors | 1.0.0 | -- | testdata/locks-requirements/unresolvable-requirements.txt | | https://osv.dev/GHSA-84pr-m4jr-85g5 | | | | | | | -| https://osv.dev/PYSEC-2024-71 | 8.7 | PyPI | flask-cors | 1.0.0 | 4.0.2 | testdata/locks-requirements/unresolvable-requirements.txt | -| https://osv.dev/GHSA-hxwh-jpp2-84pm | | | | | | | | https://osv.dev/GHSA-43qf-4rqw-9q2g | 5.3 | PyPI | flask-cors | 1.0.0 | 6.0.0 | testdata/locks-requirements/unresolvable-requirements.txt | | https://osv.dev/GHSA-7rxf-gvfg-47g4 | 4.3 | PyPI | flask-cors | 1.0.0 | 6.0.0 | testdata/locks-requirements/unresolvable-requirements.txt | | https://osv.dev/GHSA-8vgw-p6qm-5gr7 | 5.3 | PyPI | flask-cors | 1.0.0 | 6.0.0 | testdata/locks-requirements/unresolvable-requirements.txt | @@ -2387,8 +2393,8 @@ Filtered 8 vulnerabilities from output testdata/osv-scanner-partial-ignores-config.toml has unused ignores: - CVE-2019-5188 -Total 27 packages affected by 194 known vulnerabilities (22 Critical, 81 High, 64 Medium, 4 Low, 23 Unknown) from 4 ecosystems. -10 vulnerabilities can be fixed. +Total 27 packages affected by 199 known vulnerabilities (22 Critical, 81 High, 64 Medium, 4 Low, 28 Unknown) from 4 ecosystems. +11 vulnerabilities can be fixed. +---------------------------------------+------+-----------+--------------------------------+------------------------------------+-----------------------------------+---------------------------------------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | @@ -2413,6 +2419,7 @@ Total 27 packages affected by 194 known vulnerabilities (22 Critical, 81 High, 6 | https://osv.dev/GHSA-cgrx-mc8f-2prm | | | | | | | | https://osv.dev/GO-2022-0493 | 5.3 | Go | golang.org/x/sys | v0.0.0-20210817142637-7d9622a276b7 | 0.0.0-20220412211240-33da011f77ad | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/GHSA-p782-xgp4-8hr8 | | | | | | | +| https://osv.dev/GO-2026-5024 | | Go | golang.org/x/sys | v0.0.0-20210817142637-7d9622a276b7 | 0.44.0 | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/ALPINE-CVE-2022-37434 | 9.8 | Alpine | zlib | 1.2.12-r1 | -- | testdata/sbom-insecure/alpine-zlib-16.cdx.json:lib/apk/db/installed | | https://osv.dev/ALPINE-CVE-2026-22184 | 7.8 | Alpine | zlib | 1.2.12-r1 | -- | testdata/sbom-insecure/alpine-zlib-16.cdx.json:lib/apk/db/installed | | https://osv.dev/ALPINE-CVE-2026-27171 | 5.5 | Alpine | zlib | 1.2.12-r1 | -- | testdata/sbom-insecure/alpine-zlib-16.cdx.json:lib/apk/db/installed | @@ -2579,6 +2586,10 @@ Total 27 packages affected by 194 known vulnerabilities (22 Critical, 81 High, 6 | https://osv.dev/DEBIAN-CVE-2021-36770 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2023-47038 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-40909 | 5.9 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42496 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42497 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-8376 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-9538 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5135-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3072-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3189-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -2636,8 +2647,8 @@ Filtered 6 vulnerabilities from output testdata/osv-scanner-partial-ignores-config.toml has unused ignores: - CVE-2019-5188 -Total 24 packages affected by 186 known vulnerabilities (20 Critical, 78 High, 61 Medium, 4 Low, 23 Unknown) from 3 ecosystems. -10 vulnerabilities can be fixed. +Total 24 packages affected by 191 known vulnerabilities (20 Critical, 78 High, 61 Medium, 4 Low, 28 Unknown) from 3 ecosystems. +11 vulnerabilities can be fixed. +---------------------------------------+------+-----------+--------------------------------+------------------------------------+-----------------------------------+-------------------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | @@ -2662,6 +2673,7 @@ Total 24 packages affected by 186 known vulnerabilities (20 Critical, 78 High, 6 | https://osv.dev/GHSA-cgrx-mc8f-2prm | | | | | | | | https://osv.dev/GO-2022-0493 | 5.3 | Go | golang.org/x/sys | v0.0.0-20210817142637-7d9622a276b7 | 0.0.0-20220412211240-33da011f77ad | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/GHSA-p782-xgp4-8hr8 | | | | | | | +| https://osv.dev/GO-2026-5024 | | Go | golang.org/x/sys | v0.0.0-20210817142637-7d9622a276b7 | 0.44.0 | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/ALPINE-CVE-2026-40200 | 8.1 | Alpine | musl | 1.2.3-r4 | -- | testdata/sbom-insecure/alpine.cdx.xml | | https://osv.dev/ALPINE-CVE-2026-6042 | 4.8 | Alpine | musl | 1.2.3-r4 | -- | testdata/sbom-insecure/alpine.cdx.xml | | https://osv.dev/ALPINE-CVE-2022-37434 | 9.8 | Alpine | zlib | 1.2.10-r0 | -- | testdata/sbom-insecure/alpine.cdx.xml | @@ -2820,6 +2832,10 @@ Total 24 packages affected by 186 known vulnerabilities (20 Critical, 78 High, 6 | https://osv.dev/DEBIAN-CVE-2021-36770 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2023-47038 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-40909 | 5.9 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42496 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42497 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-8376 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-9538 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5135-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3072-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3189-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -4970,7 +4986,7 @@ Filtered 1 local/unscannable package/s from the scan. Loaded Debian local db from /osv-scanner/Debian/all.zip Loaded Go local db from /osv-scanner/Go/all.zip -Total 22 packages affected by 185 known vulnerabilities (19 Critical, 77 High, 60 Medium, 4 Low, 25 Unknown) from 2 ecosystems. +Total 22 packages affected by 188 known vulnerabilities (19 Critical, 77 High, 60 Medium, 4 Low, 28 Unknown) from 2 ecosystems. 12 vulnerabilities can be fixed. +---------------------------------------+------+-----------+--------------------------------+------------------------------------+-----------------------------------+-------------------------------------------------+ @@ -5154,7 +5170,10 @@ Total 22 packages affected by 185 known vulnerabilities (19 Critical, 77 High, 6 | https://osv.dev/DEBIAN-CVE-2021-36770 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2023-47038 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-40909 | 5.9 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42496 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42497 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2026-8376 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-9538 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5135-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3072-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3189-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -5205,7 +5224,7 @@ Filtered 1 local/unscannable package/s from the scan. Loaded Debian local db from /osv-scanner/Debian/all.zip Loaded Go local db from /osv-scanner/Go/all.zip -Total 22 packages affected by 185 known vulnerabilities (19 Critical, 77 High, 60 Medium, 4 Low, 25 Unknown) from 2 ecosystems. +Total 22 packages affected by 188 known vulnerabilities (19 Critical, 77 High, 60 Medium, 4 Low, 28 Unknown) from 2 ecosystems. 12 vulnerabilities can be fixed. +---------------------------------------+------+-----------+--------------------------------+------------------------------------+-----------------------------------+-------------------------------------------------+ @@ -5389,7 +5408,10 @@ Total 22 packages affected by 185 known vulnerabilities (19 Critical, 77 High, 6 | https://osv.dev/DEBIAN-CVE-2021-36770 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2023-47038 | 7.8 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-40909 | 5.9 | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42496 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-42497 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2026-8376 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-9538 | | Debian | perl | 5.24.1-3+deb9u7 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5135-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3072-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3189-1 | | Debian | postgresql-11 | 11.15-1.pgdg90+1 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml index 41a9db07389..c9357cd172a 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml @@ -1158,15 +1158,15 @@ interactions: }, { "id": "DRUPAL-CORE-2026-001", - "modified": "2026-04-15T19:57:30.305696Z" + "modified": "2026-05-21T09:26:01.119793Z" }, { "id": "DRUPAL-CORE-2026-002", - "modified": "2026-04-15T19:45:11.714415Z" + "modified": "2026-05-21T09:26:08.698854Z" }, { "id": "DRUPAL-CORE-2026-004", - "modified": "2026-05-20T18:45:03.974160Z" + "modified": "2026-05-21T19:00:03.853407Z" }, { "id": "GHSA-83v7-c2cf-p9c2", @@ -3246,7 +3246,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 23664 + content_length: 24013 body: | { "results": [ @@ -3558,6 +3558,10 @@ interactions: { "id": "GO-2022-0493", "modified": "2026-02-04T03:42:54.589715Z" + }, + { + "id": "GO-2026-5024", + "modified": "2026-05-22T19:45:12.763756Z" } ] }, @@ -3633,7 +3637,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-41989", - "modified": "2026-05-18T21:00:35.644624Z" + "modified": "2026-05-22T23:00:08.627309Z" }, { "id": "DEBIAN-CVE-2026-41990", @@ -4541,6 +4545,22 @@ interactions: "id": "DEBIAN-CVE-2025-40909", "modified": "2026-04-28T20:30:31.167223Z" }, + { + "id": "DEBIAN-CVE-2026-42496", + "modified": "2026-05-26T08:48:11.574624Z" + }, + { + "id": "DEBIAN-CVE-2026-42497", + "modified": "2026-05-26T08:48:20.174717Z" + }, + { + "id": "DEBIAN-CVE-2026-8376", + "modified": "2026-05-26T08:48:07.986014Z" + }, + { + "id": "DEBIAN-CVE-2026-9538", + "modified": "2026-05-26T08:48:18.172113Z" + }, { "id": "DLA-3926-1", "modified": "2026-03-09T01:20:46.118633Z" @@ -4843,7 +4863,7 @@ interactions: } headers: Content-Length: - - "23664" + - "24013" Content-Type: - application/json status: 200 OK @@ -4984,7 +5004,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-05-15T10:59:21.920937Z" + "modified": "2026-05-21T10:29:29.571049Z" }, { "id": "GO-2025-4015", @@ -4992,7 +5012,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-05-20T10:44:13.479815Z" + "modified": "2026-05-21T10:29:29.263573Z" }, { "id": "GO-2025-4175", @@ -5000,7 +5020,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-05-20T10:44:11.616660Z" + "modified": "2026-05-21T10:29:30.061114Z" }, { "id": "GO-2026-4340", @@ -5008,15 +5028,15 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-05-20T10:44:14.114531Z" + "modified": "2026-05-21T10:29:30.657427Z" }, { "id": "GO-2026-4342", - "modified": "2026-05-15T10:59:24.578996Z" + "modified": "2026-05-21T10:29:30.414735Z" }, { "id": "GO-2026-4601", - "modified": "2026-05-20T10:44:12.126892Z" + "modified": "2026-05-26T10:44:20.421456Z" }, { "id": "GO-2026-4602", @@ -5028,7 +5048,7 @@ interactions: }, { "id": "GO-2026-4864", - "modified": "2026-05-20T10:44:11.859569Z" + "modified": "2026-05-26T10:44:20.254676Z" }, { "id": "GO-2026-4865", @@ -5040,7 +5060,7 @@ interactions: }, { "id": "GO-2026-4870", - "modified": "2026-05-20T10:44:12.672282Z" + "modified": "2026-05-26T10:44:20.581519Z" }, { "id": "GO-2026-4918", @@ -5048,11 +5068,11 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-05-20T10:44:13.405941Z" + "modified": "2026-05-26T10:44:20.870574Z" }, { "id": "GO-2026-4947", - "modified": "2026-05-20T10:44:14.184571Z" + "modified": "2026-05-26T10:44:20.335619Z" }, { "id": "GO-2026-4971", @@ -6751,7 +6771,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 5014 + content_length: 5079 body: | { "results": [ @@ -7071,9 +7091,13 @@ interactions: "id": "PYSEC-2020-43", "modified": "2025-10-09T07:22:50.566622Z" }, + { + "id": "PYSEC-2024-260", + "modified": "2026-05-21T15:00:12.457440Z" + }, { "id": "PYSEC-2024-271", - "modified": "2026-05-20T09:19:00.391910Z" + "modified": "2026-05-21T15:00:12.481016Z" }, { "id": "PYSEC-2024-71", @@ -7093,7 +7117,7 @@ interactions: } headers: Content-Length: - - "5014" + - "5079" Content-Type: - application/json status: 200 OK diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml index b4c29f9a982..8ca8bda29eb 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml @@ -132,7 +132,7 @@ interactions: }, { "id": "OSV-2024-340", - "modified": "2026-05-20T14:30:40.458085Z" + "modified": "2026-05-26T14:22:06.907413Z" } ] }, @@ -229,7 +229,7 @@ interactions: }, { "id": "CVE-2025-69419", - "modified": "2026-04-16T04:30:17.322662Z" + "modified": "2026-05-26T16:14:28.280291Z" }, { "id": "CVE-2025-69420", diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml index 012b3eabe6f..e523b7aec95 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml @@ -1416,7 +1416,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 23664 + content_length: 24013 body: | { "results": [ @@ -1728,6 +1728,10 @@ interactions: { "id": "GO-2022-0493", "modified": "2026-02-04T03:42:54.589715Z" + }, + { + "id": "GO-2026-5024", + "modified": "2026-05-22T19:45:12.763756Z" } ] }, @@ -1803,7 +1807,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-41989", - "modified": "2026-05-18T21:00:35.644624Z" + "modified": "2026-05-22T23:00:08.627309Z" }, { "id": "DEBIAN-CVE-2026-41990", @@ -2711,6 +2715,22 @@ interactions: "id": "DEBIAN-CVE-2025-40909", "modified": "2026-04-28T20:30:31.167223Z" }, + { + "id": "DEBIAN-CVE-2026-42496", + "modified": "2026-05-26T08:48:11.574624Z" + }, + { + "id": "DEBIAN-CVE-2026-42497", + "modified": "2026-05-26T08:48:20.174717Z" + }, + { + "id": "DEBIAN-CVE-2026-8376", + "modified": "2026-05-26T08:48:07.986014Z" + }, + { + "id": "DEBIAN-CVE-2026-9538", + "modified": "2026-05-26T08:48:18.172113Z" + }, { "id": "DLA-3926-1", "modified": "2026-03-09T01:20:46.118633Z" @@ -3013,7 +3033,7 @@ interactions: } headers: Content-Length: - - "23664" + - "24013" Content-Type: - application/json status: 200 OK @@ -4084,7 +4104,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 22765 + content_length: 23114 body: | { "results": [ @@ -4364,6 +4384,10 @@ interactions: { "id": "GO-2022-0493", "modified": "2026-02-04T03:42:54.589715Z" + }, + { + "id": "GO-2026-5024", + "modified": "2026-05-22T19:45:12.763756Z" } ] }, @@ -4439,7 +4463,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-41989", - "modified": "2026-05-18T21:00:35.644624Z" + "modified": "2026-05-22T23:00:08.627309Z" }, { "id": "DEBIAN-CVE-2026-41990", @@ -5347,6 +5371,22 @@ interactions: "id": "DEBIAN-CVE-2025-40909", "modified": "2026-04-28T20:30:31.167223Z" }, + { + "id": "DEBIAN-CVE-2026-42496", + "modified": "2026-05-26T08:48:11.574624Z" + }, + { + "id": "DEBIAN-CVE-2026-42497", + "modified": "2026-05-26T08:48:20.174717Z" + }, + { + "id": "DEBIAN-CVE-2026-8376", + "modified": "2026-05-26T08:48:07.986014Z" + }, + { + "id": "DEBIAN-CVE-2026-9538", + "modified": "2026-05-26T08:48:18.172113Z" + }, { "id": "DLA-3926-1", "modified": "2026-03-09T01:20:46.118633Z" @@ -5601,7 +5641,7 @@ interactions: } headers: Content-Length: - - "22765" + - "23114" Content-Type: - application/json status: 200 OK diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml index 1a4f50c0c84..01bd35c195d 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml @@ -308,7 +308,7 @@ interactions: }, { "id": "CVE-2025-69419", - "modified": "2026-04-16T04:30:17.322662Z" + "modified": "2026-05-26T16:14:28.280291Z" }, { "id": "CVE-2025-69420", diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml index 8a5205dbf5e..68beaad18f5 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml @@ -1511,167 +1511,6 @@ interactions: status: 200 OK code: 200 duration: 0s - - request: - proto: HTTP/1.1 - proto_major: 1 - proto_minor: 1 - content_length: 997 - host: api.osv.dev - body: | - { - "queries": [ - { - "package": { - "ecosystem": "PyPI", - "name": "click" - }, - "version": "8.4.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "flask" - }, - "version": "1.0.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "flask-cors" - }, - "version": "1.0.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "itsdangerous" - }, - "version": "2.2.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "jinja2" - }, - "version": "3.1.6" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "markupsafe" - }, - "version": "3.0.3" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "pandas" - }, - "version": "0.23.4" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "werkzeug" - }, - "version": "3.1.8" - } - ] - } - headers: - Content-Type: - - application/json - X-Test-Name: - - TestCommand_Transitive/requirements.txt_resolution_fallback - url: https://api.osv.dev/v1/querybatch - method: POST - response: - proto: HTTP/2.0 - proto_major: 2 - proto_minor: 0 - content_length: 945 - body: | - { - "results": [ - {}, - { - "vulns": [ - { - "id": "GHSA-68rp-wp8r-4726", - "modified": "2026-02-23T23:43:45.778179Z" - }, - { - "id": "GHSA-m2qf-hxjv-5gpq", - "modified": "2025-02-21T05:42:17.337040Z" - }, - { - "id": "PYSEC-2023-62", - "modified": "2023-11-08T04:12:28.231927Z" - } - ] - }, - { - "vulns": [ - { - "id": "GHSA-43qf-4rqw-9q2g", - "modified": "2026-02-04T02:30:19.251090Z" - }, - { - "id": "GHSA-7rxf-gvfg-47g4", - "modified": "2026-02-04T04:27:15.173118Z" - }, - { - "id": "GHSA-84pr-m4jr-85g5", - "modified": "2026-05-20T08:11:24.907016Z" - }, - { - "id": "GHSA-8vgw-p6qm-5gr7", - "modified": "2026-02-04T02:42:09.564281Z" - }, - { - "id": "GHSA-hxwh-jpp2-84pm", - "modified": "2026-05-19T20:30:23.753027Z" - }, - { - "id": "GHSA-xc3p-ff3m-f46v", - "modified": "2024-09-20T20:01:25.449661Z" - }, - { - "id": "PYSEC-2020-43", - "modified": "2025-10-09T07:22:50.566622Z" - }, - { - "id": "PYSEC-2024-271", - "modified": "2026-05-20T09:19:00.391910Z" - }, - { - "id": "PYSEC-2024-71", - "modified": "2026-05-19T05:26:16.591908Z" - } - ] - }, - {}, - {}, - {}, - { - "vulns": [ - { - "id": "PYSEC-2020-73", - "modified": "2023-11-08T04:02:12.263851Z" - } - ] - }, - {} - ] - } - headers: - Content-Length: - - "945" - Content-Type: - - application/json - status: 200 OK - code: 200 - duration: 0s - request: proto: HTTP/1.1 proto_major: 1 @@ -1865,294 +1704,7 @@ interactions: "ecosystem": "PyPI", "name": "click" }, - "version": "8.4.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "django" - }, - "version": "1.11.29" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "flask" - }, - "version": "1.0.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "idna" - }, - "version": "2.7.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "itsdangerous" - }, - "version": "2.2.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "jinja2" - }, - "version": "3.1.6" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "markupsafe" - }, - "version": "3.0.3" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "pytz" - }, - "version": "2026.2.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "requests" - }, - "version": "2.20.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "urllib3" - }, - "version": "1.24.3" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "werkzeug" - }, - "version": "3.1.8" - } - ] - } - headers: - Content-Type: - - application/json - X-Test-Name: - - TestCommand_Transitive/requirements.txt_transitive_default - url: https://api.osv.dev/v1/querybatch - method: POST - response: - proto: HTTP/2.0 - proto_major: 2 - proto_minor: 0 - content_length: 2358 - body: | - { - "results": [ - {}, - {}, - {}, - { - "vulns": [ - { - "id": "GHSA-68w8-qjq3-2gfm", - "modified": "2024-09-20T15:46:52.557962Z" - }, - { - "id": "GHSA-6w2r-r2m5-xq5w", - "modified": "2026-05-20T08:11:10.875803Z" - }, - { - "id": "GHSA-7xr5-9hcq-chf9", - "modified": "2026-02-04T03:48:05.224740Z" - }, - { - "id": "GHSA-8x94-hmjh-97hq", - "modified": "2026-02-04T02:45:55.690257Z" - }, - { - "id": "GHSA-frmv-pr5f-9mcr", - "modified": "2026-05-20T08:11:38.853710Z" - }, - { - "id": "GHSA-qw25-v68c-qjf3", - "modified": "2026-05-20T08:11:10.816089Z" - }, - { - "id": "GHSA-rrqc-c2jx-6jgv", - "modified": "2024-10-30T19:23:59.139649Z" - }, - { - "id": "PYSEC-2021-98", - "modified": "2023-12-06T01:01:16.755410Z" - } - ] - }, - { - "vulns": [ - { - "id": "GHSA-68rp-wp8r-4726", - "modified": "2026-02-23T23:43:45.778179Z" - }, - { - "id": "GHSA-m2qf-hxjv-5gpq", - "modified": "2025-02-21T05:42:17.337040Z" - }, - { - "id": "PYSEC-2023-62", - "modified": "2023-11-08T04:12:28.231927Z" - } - ] - }, - { - "vulns": [ - { - "id": "GHSA-65pc-fj4g-8rjx", - "modified": "2026-05-19T14:45:16.378872Z" - }, - { - "id": "GHSA-jjg7-2v4v-x38h", - "modified": "2026-02-04T03:49:45.087439Z" - }, - { - "id": "PYSEC-2024-60", - "modified": "2024-07-11T17:42:33.704488Z" - } - ] - }, - {}, - {}, - {}, - {}, - { - "vulns": [ - { - "id": "GHSA-9hjg-9r4m-mvj7", - "modified": "2026-02-04T03:44:00.676479Z" - }, - { - "id": "GHSA-9wx4-h78v-vm56", - "modified": "2026-02-04T02:43:42.271895Z" - }, - { - "id": "GHSA-gc5v-m9x4-r6x2", - "modified": "2026-03-27T22:17:33.595885Z" - }, - { - "id": "GHSA-j8r2-6x86-q33q", - "modified": "2026-02-04T03:34:13.807518Z" - }, - { - "id": "PYSEC-2023-74", - "modified": "2023-11-08T04:12:35.436175Z" - } - ] - }, - { - "vulns": [ - { - "id": "GHSA-2xpw-w6gg-jr37", - "modified": "2026-02-04T02:36:12.983430Z" - }, - { - "id": "GHSA-34jh-p97f-mpxf", - "modified": "2026-02-04T03:37:44.850742Z" - }, - { - "id": "GHSA-38jv-5279-wg99", - "modified": "2026-02-04T03:51:36.162029Z" - }, - { - "id": "GHSA-g4mx-q9vg-27p4", - "modified": "2026-02-04T03:30:16.767903Z" - }, - { - "id": "GHSA-gm62-xv2j-4w53", - "modified": "2026-02-04T03:37:15.919661Z" - }, - { - "id": "GHSA-pq67-6m6q-mj2v", - "modified": "2026-02-04T04:38:01.163387Z" - }, - { - "id": "GHSA-qccp-gfcp-xxvc", - "modified": "2026-05-20T08:11:43.145797Z" - }, - { - "id": "GHSA-v845-jxx5-vc9f", - "modified": "2026-02-04T02:58:30.152562Z" - }, - { - "id": "GHSA-wqvq-5m8c-6g24", - "modified": "2024-11-18T22:47:07.792720Z" - }, - { - "id": "PYSEC-2020-148", - "modified": "2023-11-08T04:03:14.251187Z" - }, - { - "id": "PYSEC-2021-108", - "modified": "2023-11-08T04:06:04.829992Z" - }, - { - "id": "PYSEC-2023-192", - "modified": "2023-11-08T04:13:33.452167Z" - }, - { - "id": "PYSEC-2023-212", - "modified": "2023-11-08T04:13:39.165450Z" - }, - { - "id": "PYSEC-2026-141", - "modified": "2026-05-20T09:19:20.983812Z" - } - ] - }, - {} - ] - } - headers: - Content-Length: - - "2358" - Content-Type: - - application/json - status: 200 OK - code: 200 - duration: 0s - - request: - proto: HTTP/1.1 - proto_major: 1 - proto_minor: 1 - content_length: 1604 - host: api.osv.dev - body: | - { - "queries": [ - { - "package": { - "ecosystem": "PyPI", - "name": "certifi" - }, - "version": "2026.5.20" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "chardet" - }, - "version": "3.0.4" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "click" - }, - "version": "8.4.1" + "version": "8.4.1" }, { "package": { @@ -2411,293 +1963,6 @@ interactions: status: 200 OK code: 200 duration: 0s - - request: - proto: HTTP/1.1 - proto_major: 1 - proto_minor: 1 - content_length: 1598 - host: api.osv.dev - body: | - { - "queries": [ - { - "package": { - "ecosystem": "PyPI", - "name": "certifi" - }, - "version": "2026.5.20" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "chardet" - }, - "version": "3.0.4" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "click" - }, - "version": "8.4.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "django" - }, - "version": "1.11.29" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "flask" - }, - "version": "1.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "idna" - }, - "version": "2.7" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "itsdangerous" - }, - "version": "2.2.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "jinja2" - }, - "version": "3.1.6" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "markupsafe" - }, - "version": "3.0.3" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "pytz" - }, - "version": "2026.2" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "requests" - }, - "version": "2.20.0" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "urllib3" - }, - "version": "1.24.3" - }, - { - "package": { - "ecosystem": "PyPI", - "name": "werkzeug" - }, - "version": "3.1.8" - } - ] - } - headers: - Content-Type: - - application/json - X-Test-Name: - - TestCommand_Transitive/requirements.txt_transitive_native_source - url: https://api.osv.dev/v1/querybatch - method: POST - response: - proto: HTTP/2.0 - proto_major: 2 - proto_minor: 0 - content_length: 2358 - body: | - { - "results": [ - {}, - {}, - {}, - { - "vulns": [ - { - "id": "GHSA-68w8-qjq3-2gfm", - "modified": "2024-09-20T15:46:52.557962Z" - }, - { - "id": "GHSA-6w2r-r2m5-xq5w", - "modified": "2026-05-20T08:11:10.875803Z" - }, - { - "id": "GHSA-7xr5-9hcq-chf9", - "modified": "2026-02-04T03:48:05.224740Z" - }, - { - "id": "GHSA-8x94-hmjh-97hq", - "modified": "2026-02-04T02:45:55.690257Z" - }, - { - "id": "GHSA-frmv-pr5f-9mcr", - "modified": "2026-05-20T08:11:38.853710Z" - }, - { - "id": "GHSA-qw25-v68c-qjf3", - "modified": "2026-05-20T08:11:10.816089Z" - }, - { - "id": "GHSA-rrqc-c2jx-6jgv", - "modified": "2024-10-30T19:23:59.139649Z" - }, - { - "id": "PYSEC-2021-98", - "modified": "2023-12-06T01:01:16.755410Z" - } - ] - }, - { - "vulns": [ - { - "id": "GHSA-68rp-wp8r-4726", - "modified": "2026-02-23T23:43:45.778179Z" - }, - { - "id": "GHSA-m2qf-hxjv-5gpq", - "modified": "2025-02-21T05:42:17.337040Z" - }, - { - "id": "PYSEC-2023-62", - "modified": "2023-11-08T04:12:28.231927Z" - } - ] - }, - { - "vulns": [ - { - "id": "GHSA-65pc-fj4g-8rjx", - "modified": "2026-05-19T14:45:16.378872Z" - }, - { - "id": "GHSA-jjg7-2v4v-x38h", - "modified": "2026-02-04T03:49:45.087439Z" - }, - { - "id": "PYSEC-2024-60", - "modified": "2024-07-11T17:42:33.704488Z" - } - ] - }, - {}, - {}, - {}, - {}, - { - "vulns": [ - { - "id": "GHSA-9hjg-9r4m-mvj7", - "modified": "2026-02-04T03:44:00.676479Z" - }, - { - "id": "GHSA-9wx4-h78v-vm56", - "modified": "2026-02-04T02:43:42.271895Z" - }, - { - "id": "GHSA-gc5v-m9x4-r6x2", - "modified": "2026-03-27T22:17:33.595885Z" - }, - { - "id": "GHSA-j8r2-6x86-q33q", - "modified": "2026-02-04T03:34:13.807518Z" - }, - { - "id": "PYSEC-2023-74", - "modified": "2023-11-08T04:12:35.436175Z" - } - ] - }, - { - "vulns": [ - { - "id": "GHSA-2xpw-w6gg-jr37", - "modified": "2026-02-04T02:36:12.983430Z" - }, - { - "id": "GHSA-34jh-p97f-mpxf", - "modified": "2026-02-04T03:37:44.850742Z" - }, - { - "id": "GHSA-38jv-5279-wg99", - "modified": "2026-02-04T03:51:36.162029Z" - }, - { - "id": "GHSA-g4mx-q9vg-27p4", - "modified": "2026-02-04T03:30:16.767903Z" - }, - { - "id": "GHSA-gm62-xv2j-4w53", - "modified": "2026-02-04T03:37:15.919661Z" - }, - { - "id": "GHSA-pq67-6m6q-mj2v", - "modified": "2026-02-04T04:38:01.163387Z" - }, - { - "id": "GHSA-qccp-gfcp-xxvc", - "modified": "2026-05-20T08:11:43.145797Z" - }, - { - "id": "GHSA-v845-jxx5-vc9f", - "modified": "2026-02-04T02:58:30.152562Z" - }, - { - "id": "GHSA-wqvq-5m8c-6g24", - "modified": "2024-11-18T22:47:07.792720Z" - }, - { - "id": "PYSEC-2020-148", - "modified": "2023-11-08T04:03:14.251187Z" - }, - { - "id": "PYSEC-2021-108", - "modified": "2023-11-08T04:06:04.829992Z" - }, - { - "id": "PYSEC-2023-192", - "modified": "2023-11-08T04:13:33.452167Z" - }, - { - "id": "PYSEC-2023-212", - "modified": "2023-11-08T04:13:39.165450Z" - }, - { - "id": "PYSEC-2026-141", - "modified": "2026-05-20T09:19:20.983812Z" - } - ] - }, - {} - ] - } - headers: - Content-Length: - - "2358" - Content-Type: - - application/json - status: 200 OK - code: 200 - duration: 0s - request: proto: HTTP/1.1 proto_major: 1