You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: cmd/osv-scanner/scan/source/__snapshots__/command_test.snap
+46-48Lines changed: 46 additions & 48 deletions
Original file line number
Diff line number
Diff line change
@@ -5895,17 +5895,9 @@ Filtered 2 ignored package/s from the scan.
5895
5895
<tempdir>/nested-2/osv-scanner-test.toml has been updated to ignore 3 vulnerabilities
5896
5896
<tempdir>/nested-3/osv-scanner-test.toml has been updated to ignore 1 vulnerability
5897
5897
<tempdir>/osv-scanner-test.toml has been updated to ignore 2 vulnerabilities
5898
-
CVE-2021-23424 and 1 alias have been filtered out because: Test manifest file (package-lock.json)
5899
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
5900
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
5901
-
Filtered 3 vulnerabilities from output
5902
-
<tempdir>/nested-2/osv-scanner-test.toml has unused ignores:
5903
-
- GHSA-2g4f-4pwh-qvx6
5904
-
<tempdir>/nested-3/osv-scanner-test.toml has unused ignores:
5905
-
- GHSA-2g4f-4pwh-qvx6
5906
5898
5907
-
Total 7 packages affected by 8 known vulnerabilities (0 Critical, 3 High, 5 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
5908
-
8 vulnerabilities can be fixed.
5899
+
Total 9 packages affected by 11 known vulnerabilities (0 Critical, 4 High, 7 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
5900
+
11 vulnerabilities can be fixed.
5909
5901
5910
5902
RubyGems
5911
5903
@@ -5919,7 +5911,7 @@ lockfile:<tempdir>/Gemfile.lock: found 1 package with issues
5919
5911
5920
5912
npm
5921
5913
5922
-
lockfile:<tempdir>/nested-1/package-lock.json: found 2 packages with issues
5914
+
lockfile:<tempdir>/nested-1/package-lock.json: found 3 packages with issues
5923
5915
5924
5916
ajv@6.0.0 has the following known vulnerabilities:
5925
5917
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
@@ -5929,19 +5921,27 @@ lockfile:<tempdir>/nested-1/package-lock.json: found 2 packages with issues
5929
5921
ajv@8.0.0 has the following known vulnerabilities:
5930
5922
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
5931
5923
Severity: '5.5'; Minimal Fix Version: '8.18.0';
5924
+
ansi-html@0.0.1 has the following known vulnerabilities:
5925
+
GHSA-whgm-jr23-g3j9: Uncontrolled Resource Consumption in ansi-html
5926
+
Severity: '7.5'; Minimal Fix Version: '0.0.8';
5932
5927
5933
-
3 known vulnerabilities found in lockfile:<tempdir>/nested-1/package-lock.json
5928
+
4 known vulnerabilities found in lockfile:<tempdir>/nested-1/package-lock.json
5934
5929
5935
-
lockfile:<tempdir>/nested-2/package-lock.json: found 2 packages with issues
5930
+
lockfile:<tempdir>/nested-2/package-lock.json: found 3 packages with issues
5936
5931
5937
5932
ajv@6.0.0 has the following known vulnerabilities:
5933
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
5934
+
Severity: '5.5'; Minimal Fix Version: '6.14.0';
5938
5935
GHSA-v88g-cgmw-v5xw: Prototype Pollution in Ajv
5939
5936
Severity: '5.6'; Minimal Fix Version: '6.12.3';
5937
+
ajv@8.0.0 has the following known vulnerabilities:
5938
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
5939
+
Severity: '5.5'; Minimal Fix Version: '8.18.0';
5940
5940
ansi-html@0.0.1 has the following known vulnerabilities:
5941
5941
GHSA-whgm-jr23-g3j9: Uncontrolled Resource Consumption in ansi-html
5942
5942
Severity: '7.5'; Minimal Fix Version: '0.0.8';
5943
5943
5944
-
2 known vulnerabilities found in lockfile:<tempdir>/nested-2/package-lock.json
5944
+
4 known vulnerabilities found in lockfile:<tempdir>/nested-2/package-lock.json
5945
5945
5946
5946
lockfile:<tempdir>/nested-3/package-lock.json: found 1 package with issues
5947
5947
@@ -6072,8 +6072,6 @@ Package npm/ajv/6.0.0 has been filtered out because: (no reason given)
6072
6072
Package npm/ajv/8.0.0 has been filtered out because: (no reason given)
6073
6073
Filtered 2 ignored package/s from the scan.
6074
6074
<tempdir>/nested-3/osv-scanner-test.toml has been updated to ignore 1 vulnerability
6075
-
<tempdir>/nested-3/osv-scanner-test.toml has unused ignores:
6076
-
- GHSA-2g4f-4pwh-qvx6
6077
6075
6078
6076
Total 9 packages affected by 11 known vulnerabilities (0 Critical, 4 High, 7 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6079
6077
11 vulnerabilities can be fixed.
@@ -6277,16 +6275,9 @@ Filtered 2 ignored package/s from the scan.
6277
6275
<tempdir>/nested-2/osv-scanner-test.toml has been updated to ignore 3 vulnerabilities
6278
6276
<tempdir>/nested-3/osv-scanner-test.toml has been updated to ignore 1 vulnerability
6279
6277
<tempdir>/osv-scanner-test.toml has been updated to ignore 2 vulnerabilities
6280
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6281
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6282
-
Filtered 2 vulnerabilities from output
6283
-
<tempdir>/nested-2/osv-scanner-test.toml has unused ignores:
6284
-
- GHSA-2g4f-4pwh-qvx6
6285
-
<tempdir>/nested-3/osv-scanner-test.toml has unused ignores:
6286
-
- GHSA-2g4f-4pwh-qvx6
6287
6278
6288
-
Total 8 packages affected by 9 known vulnerabilities (0 Critical, 4 High, 5 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6289
-
9 vulnerabilities can be fixed.
6279
+
Total 9 packages affected by 11 known vulnerabilities (0 Critical, 4 High, 7 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6280
+
11 vulnerabilities can be fixed.
6290
6281
6291
6282
RubyGems
6292
6283
@@ -6316,16 +6307,21 @@ lockfile:<tempdir>/nested-1/package-lock.json: found 3 packages with issues
6316
6307
6317
6308
4 known vulnerabilities found in lockfile:<tempdir>/nested-1/package-lock.json
6318
6309
6319
-
lockfile:<tempdir>/nested-2/package-lock.json: found 2 packages with issues
6310
+
lockfile:<tempdir>/nested-2/package-lock.json: found 3 packages with issues
6320
6311
6321
6312
ajv@6.0.0 has the following known vulnerabilities:
6313
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6314
+
Severity: '5.5'; Minimal Fix Version: '6.14.0';
6322
6315
GHSA-v88g-cgmw-v5xw: Prototype Pollution in Ajv
6323
6316
Severity: '5.6'; Minimal Fix Version: '6.12.3';
6317
+
ajv@8.0.0 has the following known vulnerabilities:
6318
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6319
+
Severity: '5.5'; Minimal Fix Version: '8.18.0';
6324
6320
ansi-html@0.0.1 has the following known vulnerabilities:
6325
6321
GHSA-whgm-jr23-g3j9: Uncontrolled Resource Consumption in ansi-html
6326
6322
Severity: '7.5'; Minimal Fix Version: '0.0.8';
6327
6323
6328
-
2 known vulnerabilities found in lockfile:<tempdir>/nested-2/package-lock.json
6324
+
4 known vulnerabilities found in lockfile:<tempdir>/nested-2/package-lock.json
6329
6325
6330
6326
lockfile:<tempdir>/nested-3/package-lock.json: found 1 package with issues
6331
6327
@@ -6460,18 +6456,9 @@ Scanned <tempdir>/nested-3/package-lock.json file and found 3 packages
6460
6456
Scanned <tempdir>/package-lock.json file and found 1 package
6461
6457
Warning: plugin transitivedependency/pomxml can be risky when run on untrusted artifacts. Please ensure you trust the source code and artifacts before proceeding.
6462
6458
<tempdir>/custom-config.toml has been updated to ignore 4 vulnerabilities
6463
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6464
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6465
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6466
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6467
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6468
-
GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6469
-
Filtered 6 vulnerabilities from output
6470
-
<tempdir>/custom-config.toml has unused ignores:
6471
-
- CVE-123-456-789
6472
6459
6473
-
Total 8 packages affected by 8 known vulnerabilities (0 Critical, 4 High, 4 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6474
-
8 vulnerabilities can be fixed.
6460
+
Total 11 packages affected by 14 known vulnerabilities (0 Critical, 4 High, 10 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6461
+
14 vulnerabilities can be fixed.
6475
6462
6476
6463
RubyGems
6477
6464
@@ -6485,38 +6472,53 @@ lockfile:<tempdir>/Gemfile.lock: found 1 package with issues
6485
6472
6486
6473
npm
6487
6474
6488
-
lockfile:<tempdir>/nested-1/package-lock.json: found 2 packages with issues
6475
+
lockfile:<tempdir>/nested-1/package-lock.json: found 3 packages with issues
6489
6476
6490
6477
ajv@6.0.0 has the following known vulnerabilities:
6478
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6479
+
Severity: '5.5'; Minimal Fix Version: '6.14.0';
6491
6480
GHSA-v88g-cgmw-v5xw: Prototype Pollution in Ajv
6492
6481
Severity: '5.6'; Minimal Fix Version: '6.12.3';
6482
+
ajv@8.0.0 has the following known vulnerabilities:
6483
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6484
+
Severity: '5.5'; Minimal Fix Version: '8.18.0';
6493
6485
ansi-html@0.0.1 has the following known vulnerabilities:
6494
6486
GHSA-whgm-jr23-g3j9: Uncontrolled Resource Consumption in ansi-html
6495
6487
Severity: '7.5'; Minimal Fix Version: '0.0.8';
6496
6488
6497
-
2 known vulnerabilities found in lockfile:<tempdir>/nested-1/package-lock.json
6489
+
4 known vulnerabilities found in lockfile:<tempdir>/nested-1/package-lock.json
6498
6490
6499
-
lockfile:<tempdir>/nested-2/package-lock.json: found 2 packages with issues
6491
+
lockfile:<tempdir>/nested-2/package-lock.json: found 3 packages with issues
6500
6492
6501
6493
ajv@6.0.0 has the following known vulnerabilities:
6494
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6495
+
Severity: '5.5'; Minimal Fix Version: '6.14.0';
6502
6496
GHSA-v88g-cgmw-v5xw: Prototype Pollution in Ajv
6503
6497
Severity: '5.6'; Minimal Fix Version: '6.12.3';
6498
+
ajv@8.0.0 has the following known vulnerabilities:
6499
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6500
+
Severity: '5.5'; Minimal Fix Version: '8.18.0';
6504
6501
ansi-html@0.0.1 has the following known vulnerabilities:
6505
6502
GHSA-whgm-jr23-g3j9: Uncontrolled Resource Consumption in ansi-html
6506
6503
Severity: '7.5'; Minimal Fix Version: '0.0.8';
6507
6504
6508
-
2 known vulnerabilities found in lockfile:<tempdir>/nested-2/package-lock.json
6505
+
4 known vulnerabilities found in lockfile:<tempdir>/nested-2/package-lock.json
6509
6506
6510
-
lockfile:<tempdir>/nested-3/package-lock.json: found 2 packages with issues
6507
+
lockfile:<tempdir>/nested-3/package-lock.json: found 3 packages with issues
6511
6508
6512
6509
ajv@6.0.0 has the following known vulnerabilities:
6510
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6511
+
Severity: '5.5'; Minimal Fix Version: '6.14.0';
6513
6512
GHSA-v88g-cgmw-v5xw: Prototype Pollution in Ajv
6514
6513
Severity: '5.6'; Minimal Fix Version: '6.12.3';
6514
+
ajv@8.0.0 has the following known vulnerabilities:
6515
+
GHSA-2g4f-4pwh-qvx6: ajv has ReDoS when using `$data` option
6516
+
Severity: '5.5'; Minimal Fix Version: '8.18.0';
6515
6517
ansi-html@0.0.1 has the following known vulnerabilities:
6516
6518
GHSA-whgm-jr23-g3j9: Uncontrolled Resource Consumption in ansi-html
6517
6519
Severity: '7.5'; Minimal Fix Version: '0.0.8';
6518
6520
6519
-
2 known vulnerabilities found in lockfile:<tempdir>/nested-3/package-lock.json
6521
+
4 known vulnerabilities found in lockfile:<tempdir>/nested-3/package-lock.json
6520
6522
6521
6523
lockfile:<tempdir>/package-lock.json: found 1 package with issues
6522
6524
@@ -6619,9 +6621,6 @@ Scanned <tempdir>/composer.lock file and found 0 packages
6619
6621
Scanned <tempdir>/package-lock.json file and found 1 package
6620
6622
Warning: plugin transitivedependency/pomxml can be risky when run on untrusted artifacts. Please ensure you trust the source code and artifacts before proceeding.
6621
6623
<tempdir>/custom-config.toml has been updated to ignore 2 vulnerabilities
6622
-
<tempdir>/custom-config.toml has unused ignores:
6623
-
- CVE-123-456-789
6624
-
- GHSA-2g4f-4pwh-qvx6
6625
6624
6626
6625
Total 2 packages affected by 2 known vulnerabilities (0 Critical, 1 High, 1 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6627
6626
2 vulnerabilities can be fixed.
@@ -8170,7 +8169,6 @@ Scanned <tempdir>/composer.lock file and found 1 package
8170
8169
Warning: plugin transitivedependency/pomxml can be risky when run on untrusted artifacts. Please ensure you trust the source code and artifacts before proceeding.
0 commit comments