Skip to content

fix: improve platform CPE determination logic#3470

Merged
spiffcs merged 1 commit into
anchore:mainfrom
westonsteimel:platform-cpe-parsing-fix
Jun 1, 2026
Merged

fix: improve platform CPE determination logic#3470
spiffcs merged 1 commit into
anchore:mainfrom
westonsteimel:platform-cpe-parsing-fix

Conversation

@westonsteimel

Copy link
Copy Markdown
Contributor

Ensures that CPEs are only surfaced as platforms if the versionless CPE is marked as non-vulnerable across all elements within a candidate node. This prevents unaffected ranges of a package from being marked as a platform of itself.

Ensures that CPEs are only surfaced as platforms if the versionless CPE
is marked as non-vulnerable across all elements within a candidate node.
This prevents unaffected ranges of a package from being marked as a
platform of itself.

Signed-off-by: Weston Steimel <author@code.w.steimel.me.uk>
@spiffcs spiffcs merged commit bc0447e into anchore:main Jun 1, 2026
16 checks passed
@willmurphyscode willmurphyscode added the bug Something isn't working label Jun 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants