-
-
Notifications
You must be signed in to change notification settings - Fork 135
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
findFirstFixedVersion ignores package identity: multi-package advisories leak fixed versions across packages
bugSomething isn't workingSomething isn't workingStatus: Open.#1042 In OWASP/cve-lite-cli;test: add unit coverage for src/output/debug.ts
enhancementNew feature or requestNew feature or requestfirst-timers-onlyReserved for contributors making their first contribution to this projectReserved for contributors making their first contribution to this projectgood first issueGood for newcomersGood for newcomersStatus: Open.#1029 In OWASP/cve-lite-cli;test: extend tests/time.test.ts with formatAdvisoryDbFreshness coverage
enhancementNew feature or requestNew feature or requestfirst-timers-onlyReserved for contributors making their first contribution to this projectReserved for contributors making their first contribution to this projectgood first issueGood for newcomersGood for newcomersStatus: Open.#1026 In OWASP/cve-lite-cli;test: add unit coverage for src/utils/advisory.ts
enhancementNew feature or requestNew feature or requestfirst-timers-onlyReserved for contributors making their first contribution to this projectReserved for contributors making their first contribution to this projectgood first issueGood for newcomersGood for newcomersStatus: Open.#1024 In OWASP/cve-lite-cli;test: add unit coverage for src/utils/sarif.ts
enhancementNew feature or requestNew feature or requestfirst-timers-onlyReserved for contributors making their first contribution to this projectReserved for contributors making their first contribution to this projectgood first issueGood for newcomersGood for newcomersStatus: Open.#1023 In OWASP/cve-lite-cli;feat(html-report): make package names in dependency path clickable npm links
enhancementNew feature or requestNew feature or requestfirst-timers-onlyReserved for contributors making their first contribution to this projectReserved for contributors making their first contribution to this projectgood first issueGood for newcomersGood for newcomersStatus: Open.#1020 In OWASP/cve-lite-cli;[Bug] pnpm v9 package keys starting with leading slash bypass vulnerability scanning
bugSomething isn't workingSomething isn't workingStatus: Open.#1012 In OWASP/cve-lite-cli;suggestedFixCommands emits a version that does not exist (cross-wired from another finding)
bugSomething isn't workingSomething isn't workingStatus: Open.#1007 In OWASP/cve-lite-cli;--only-used does not scope override-hygiene / maintenance findings in the --fail-on gate
documentationImprovements or additions to documentationImprovements or additions to documentationin-houseMaintainer-handled internal work - not open for contributionMaintainer-handled internal work - not open for contributionStatus: Open.#1000 In OWASP/cve-lite-cli;docs: document --base, --create-pr, and --debug in the CLI reference
documentationImprovements or additions to documentationImprovements or additions to documentationgood first issueGood for newcomersGood for newcomersStatus: Open.#993 In OWASP/cve-lite-cli;[Enhancement] Break down severity totals by dev vs production dependencies
enhancementNew feature or requestNew feature or requestin-houseMaintainer-handled internal work - not open for contributionMaintainer-handled internal work - not open for contributionStatus: Open.#991 In OWASP/cve-lite-cli;[Bug] OSV batch results are paired to query packages by array position, not identity
bugSomething isn't workingSomething isn't workingin-houseMaintainer-handled internal work - not open for contributionMaintainer-handled internal work - not open for contributionStatus: Open.#987 In OWASP/cve-lite-cli;