@@ -5985,7 +5985,112 @@ No issues found
59855985
59865986---
59875987
5988- [TestCommand_UpdateConfigIgnores_WithNoConfig - 1]
5988+ [TestCommand_UpdateConfigIgnores_WithNoConfig/all - 1]
5989+ Scanning dir <tempdir>
5990+ Scanned <tempdir>/Gemfile.lock file and found 1 package
5991+ Scanned <tempdir>/composer.lock file and found 0 packages
5992+ Scanned <tempdir>/nested-1/package-lock.json file and found 3 packages
5993+ Scanned <tempdir>/nested-2/package-lock.json file and found 3 packages
5994+ Scanned <tempdir>/package-lock.json file and found 1 package
5995+ Total 8 packages affected by 10 known vulnerabilities (0 Critical, 3 High, 7 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
5996+ 10 vulnerabilities can be fixed.
5997+
5998+
5999+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6000+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
6001+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6002+ | https://osv.dev/GHSA-wx95-c6cv-8532 | 5.3 | RubyGems | nokogiri | 1.18.9 | 1.19.1 | <tempdir>/Gemfile.lock |
6003+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 6.0.0 | 8.18.0 | <tempdir>/nested-1/package-lock.json |
6004+ | https://osv.dev/GHSA-v88g-cgmw-v5xw | 5.6 | npm | ajv | 6.0.0 | 6.12.3 | <tempdir>/nested-1/package-lock.json |
6005+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 8.0.0 | 8.18.0 | <tempdir>/nested-1/package-lock.json |
6006+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/nested-1/package-lock.json |
6007+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 6.0.0 | 8.18.0 | <tempdir>/nested-2/package-lock.json |
6008+ | https://osv.dev/GHSA-v88g-cgmw-v5xw | 5.6 | npm | ajv | 6.0.0 | 6.12.3 | <tempdir>/nested-2/package-lock.json |
6009+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 8.0.0 | 8.18.0 | <tempdir>/nested-2/package-lock.json |
6010+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/nested-2/package-lock.json |
6011+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/package-lock.json |
6012+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6013+
6014+ ---
6015+
6016+ [TestCommand_UpdateConfigIgnores_WithNoConfig/all - 2]
6017+
6018+ ---
6019+
6020+ [TestCommand_UpdateConfigIgnores_WithNoConfig/deep - 1]
6021+ Scanning dir <tempdir>
6022+ Scanned <tempdir>/Gemfile.lock file and found 1 package
6023+ Scanned <tempdir>/composer.lock file and found 0 packages
6024+ Scanned <tempdir>/nested-1/package-lock.json file and found 3 packages
6025+ Scanned <tempdir>/nested-2/package-lock.json file and found 3 packages
6026+ Scanned <tempdir>/package-lock.json file and found 1 package
6027+ Loaded filter from: <tempdir>/osv-scanner-test.toml
6028+ warning: <tempdir>/nested-2/osv-scanner-test.toml has multiple ignores for GHSA-2g4f-4pwh-qvx6 - only the first will be used!
6029+ Loaded filter from: <tempdir>/nested-2/osv-scanner-test.toml
6030+ GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6031+ GHSA-2g4f-4pwh-qvx6 and 1 alias have been filtered out because: (no reason given)
6032+ Filtered 2 vulnerabilities from output
6033+ <tempdir>/nested-2/osv-scanner-test.toml has unused ignores:
6034+ - GHSA-2g4f-4pwh-qvx6
6035+ Total 7 packages affected by 8 known vulnerabilities (0 Critical, 3 High, 5 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6036+ 8 vulnerabilities can be fixed.
6037+
6038+
6039+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6040+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
6041+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6042+ | https://osv.dev/GHSA-wx95-c6cv-8532 | 5.3 | RubyGems | nokogiri | 1.18.9 | 1.19.1 | <tempdir>/Gemfile.lock |
6043+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 6.0.0 | 8.18.0 | <tempdir>/nested-1/package-lock.json |
6044+ | https://osv.dev/GHSA-v88g-cgmw-v5xw | 5.6 | npm | ajv | 6.0.0 | 6.12.3 | <tempdir>/nested-1/package-lock.json |
6045+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 8.0.0 | 8.18.0 | <tempdir>/nested-1/package-lock.json |
6046+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/nested-1/package-lock.json |
6047+ | https://osv.dev/GHSA-v88g-cgmw-v5xw | 5.6 | npm | ajv | 6.0.0 | 6.12.3 | <tempdir>/nested-2/package-lock.json |
6048+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/nested-2/package-lock.json |
6049+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/package-lock.json |
6050+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6051+
6052+ ---
6053+
6054+ [TestCommand_UpdateConfigIgnores_WithNoConfig/deep - 2]
6055+
6056+ ---
6057+
6058+ [TestCommand_UpdateConfigIgnores_WithNoConfig/deep2 - 1]
6059+ Scanning dir <tempdir>
6060+ Scanned <tempdir>/Gemfile.lock file and found 1 package
6061+ Scanned <tempdir>/composer.lock file and found 0 packages
6062+ Scanned <tempdir>/nested-1/package-lock.json file and found 3 packages
6063+ Scanned <tempdir>/nested-2/package-lock.json file and found 3 packages
6064+ Scanned <tempdir>/package-lock.json file and found 1 package
6065+ Loaded filter from: <tempdir>/osv-scanner-test.toml
6066+ Loaded filter from: <tempdir>/nested-1/osv-scanner-test.toml
6067+ CVE-2021-23424 and 1 alias have been filtered out because: Test manifest file (package-lock.json)
6068+ Filtered 1 vulnerability from output
6069+ Total 7 packages affected by 9 known vulnerabilities (0 Critical, 2 High, 7 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6070+ 9 vulnerabilities can be fixed.
6071+
6072+
6073+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6074+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
6075+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6076+ | https://osv.dev/GHSA-wx95-c6cv-8532 | 5.3 | RubyGems | nokogiri | 1.18.9 | 1.19.1 | <tempdir>/Gemfile.lock |
6077+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 6.0.0 | 8.18.0 | <tempdir>/nested-1/package-lock.json |
6078+ | https://osv.dev/GHSA-v88g-cgmw-v5xw | 5.6 | npm | ajv | 6.0.0 | 6.12.3 | <tempdir>/nested-1/package-lock.json |
6079+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 8.0.0 | 8.18.0 | <tempdir>/nested-1/package-lock.json |
6080+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 6.0.0 | 8.18.0 | <tempdir>/nested-2/package-lock.json |
6081+ | https://osv.dev/GHSA-v88g-cgmw-v5xw | 5.6 | npm | ajv | 6.0.0 | 6.12.3 | <tempdir>/nested-2/package-lock.json |
6082+ | https://osv.dev/GHSA-2g4f-4pwh-qvx6 | 5.5 | npm | ajv | 8.0.0 | 8.18.0 | <tempdir>/nested-2/package-lock.json |
6083+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/nested-2/package-lock.json |
6084+ | https://osv.dev/GHSA-whgm-jr23-g3j9 | 7.5 | npm | ansi-html | 0.0.1 | 0.0.8 | <tempdir>/package-lock.json |
6085+ +-------------------------------------+------+-----------+-----------+---------+---------------+--------------------------------------------------------------+
6086+
6087+ ---
6088+
6089+ [TestCommand_UpdateConfigIgnores_WithNoConfig/deep2 - 2]
6090+
6091+ ---
6092+
6093+ [TestCommand_UpdateConfigIgnores_WithNoConfig/shallow - 1]
59896094Scanning dir <tempdir>
59906095Scanned <tempdir>/Gemfile.lock file and found 1 package
59916096Scanned <tempdir>/composer.lock file and found 0 packages
@@ -6003,7 +6108,7 @@ Total 2 packages affected by 2 known vulnerabilities (0 Critical, 1 High, 1 Medi
60036108
60046109---
60056110
6006- [TestCommand_UpdateConfigIgnores_WithNoConfig - 2]
6111+ [TestCommand_UpdateConfigIgnores_WithNoConfig/shallow - 2]
60076112
60086113---
60096114
0 commit comments