From 39d39420ab56eb6622dbc2cc1272a8b982c78f69 Mon Sep 17 00:00:00 2001 From: osv-robot Date: Thu, 23 Jul 2026 21:18:13 +0000 Subject: [PATCH] test: update cassettes --- .../image/__snapshots__/command_test.snap | 79 +++-- .../cassettes/TestCommand_OCIImage.yaml | 291 ++++++++++++------ .../TestCommand_OCIImage_JSONFormat.yaml | 136 ++++---- .../source/__snapshots__/command_test.snap | 48 +-- .../testdata/cassettes/TestCommand.yaml | 45 +-- .../cassettes/TestCommand_CommitSupport.yaml | 46 +-- .../TestCommand_Config_UnusedIgnores.yaml | 40 ++- .../cassettes/TestCommand_GithubActions.yaml | 62 ++-- .../TestCommand_JavareachArchive.yaml | 24 +- .../cassettes/TestCommand_MoreLockfiles.yaml | 8 +- .../cassettes/TestCommand_Transitive.yaml | 4 +- 11 files changed, 466 insertions(+), 317 deletions(-) diff --git a/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap b/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap index 16e5ed5754e..0b7c97c921d 100755 --- a/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap +++ b/cmd/osv-scanner/scan/image/__snapshots__/command_test.snap @@ -456,8 +456,8 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" Container Scanning Result (Ubuntu 22.04.5 LTS) (Based on "ubuntu" image): -Total 29 packages affected by 94 known vulnerabilities (13 Critical, 29 High, 36 Medium, 6 Low, 10 Unknown) from 1 ecosystem. -39 vulnerabilities can be fixed. +Total 29 packages affected by 90 known vulnerabilities (13 Critical, 27 High, 34 Medium, 6 Low, 10 Unknown) from 1 ecosystem. +40 vulnerabilities can be fixed. Ubuntu:22.04 @@ -476,14 +476,14 @@ Ubuntu:22.04 | gnupg2 | 2.2.27-3ubuntu2.1 | Partial fixes Available | 5 | gpgv | # 4 Layer | ubuntu | | gnutls28 | 3.7.3-4ubuntu1.5 | Fix Available | 4 | libgnutls30 | # 4 Layer | ubuntu | | gzip | 1.10-4ubuntu4.1 | Fix Available | 1 | gzip | # 4 Layer | ubuntu | -| krb5 | 1.19.2-2ubuntu0.4 | Partial fixes Available | 5 | libgssapi-krb5-2... (4) | # 4 Layer | ubuntu | +| krb5 | 1.19.2-2ubuntu0.4 | Fix Available | 3 | libgssapi-krb5-2... (4) | # 4 Layer | ubuntu | | libcap2 | 1:2.44-1ubuntu0.22.04.1 | Fix Available | 2 | libcap2 | # 4 Layer | ubuntu | | libgcrypt20 | 1.9.4-3ubuntu3 | Partial fixes Available | 2 | libgcrypt20 | # 4 Layer | ubuntu | | libtasn1-6 | 4.18.0-4build1 | Fix Available | 2 | libtasn1-6 | # 4 Layer | ubuntu | | libzstd | 1.4.8+dfsg-3build1 | No fix available | 1 | libzstd1 | # 4 Layer | ubuntu | | lz4 | 1.9.3-2build2 | No fix available | 1 | liblz4-1 | # 4 Layer | ubuntu | | ncurses | 6.3-2ubuntu0.1 | Partial fixes Available | 3 | libncurses6... (5) | # 4 Layer | ubuntu | -| openssl | 3.0.2-0ubuntu1.18 | Partial fixes Available | 7 | libssl3 | # 4 Layer | ubuntu | +| openssl | 3.0.2-0ubuntu1.18 | Fix Available | 5 | libssl3 | # 4 Layer | ubuntu | | p11-kit | 0.24.0-6build1 | No fix available | 1 | libp11-kit0 | # 4 Layer | ubuntu | | pam | 1.4.0-11ubuntu2.5 | Partial fixes Available | 3 | libpam-modules... (4) | # 4 Layer | ubuntu | | pcre2 | 10.39-3ubuntu0.1 | No fix available | 1 | libpcre2-8-0 | # 4 Layer | ubuntu | @@ -512,8 +512,8 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" Container Scanning Result (Ubuntu 22.04.5 LTS) (Based on "ubuntu" image): -Total 29 packages affected by 94 known vulnerabilities (13 Critical, 29 High, 36 Medium, 6 Low, 10 Unknown) from 1 ecosystem. -39 vulnerabilities can be fixed. +Total 29 packages affected by 90 known vulnerabilities (13 Critical, 27 High, 34 Medium, 6 Low, 10 Unknown) from 1 ecosystem. +41 vulnerabilities can be fixed. Ubuntu:22.04 @@ -532,14 +532,14 @@ Ubuntu:22.04 | gnupg2 | 2.2.27-3ubuntu2.1 | Partial fixes Available | 5 | gpgv | # 4 Layer | ubuntu | | gnutls28 | 3.7.3-4ubuntu1.5 | Fix Available | 4 | libgnutls30 | # 4 Layer | ubuntu | | gzip | 1.10-4ubuntu4.1 | Fix Available | 1 | gzip | # 4 Layer | ubuntu | -| krb5 | 1.19.2-2ubuntu0.4 | Partial fixes Available | 5 | libgssapi-krb5-2... (4) | # 4 Layer | ubuntu | +| krb5 | 1.19.2-2ubuntu0.4 | Fix Available | 3 | libgssapi-krb5-2... (4) | # 4 Layer | ubuntu | | libcap2 | 1:2.44-1ubuntu0.22.04.1 | Fix Available | 2 | libcap2 | # 4 Layer | ubuntu | | libgcrypt20 | 1.9.4-3ubuntu3 | Partial fixes Available | 2 | libgcrypt20 | # 4 Layer | ubuntu | | libtasn1-6 | 4.18.0-4build1 | Fix Available | 2 | libtasn1-6 | # 4 Layer | ubuntu | | libzstd | 1.4.8+dfsg-3build1 | No fix available | 1 | libzstd1 | # 4 Layer | ubuntu | | lz4 | 1.9.3-2build2 | No fix available | 1 | liblz4-1 | # 4 Layer | ubuntu | | ncurses | 6.3-2ubuntu0.1 | Partial fixes Available | 3 | libncurses6... (5) | # 4 Layer | ubuntu | -| openssl | 3.0.2-0ubuntu1.18 | Partial fixes Available | 7 | libssl3 | # 4 Layer | ubuntu | +| openssl | 3.0.2-0ubuntu1.18 | Fix Available | 5 | libssl3 | # 4 Layer | ubuntu | | p11-kit | 0.24.0-6build1 | No fix available | 1 | libp11-kit0 | # 4 Layer | ubuntu | | pam | 1.4.0-11ubuntu2.5 | Partial fixes Available | 3 | libpam-modules... (4) | # 4 Layer | ubuntu | | pcre2 | 10.39-3ubuntu0.1 | No fix available | 1 | libpcre2-8-0 | # 4 Layer | ubuntu | @@ -587,8 +587,8 @@ Scanning local image tarball "./testdata/test-ubuntu-with-packages.tar" Container Scanning Result (Ubuntu 22.04.5 LTS) (Based on "ubuntu" image): -Total 30 packages affected by 96 known vulnerabilities (13 Critical, 31 High, 36 Medium, 6 Low, 10 Unknown) from 1 ecosystem. -39 vulnerabilities can be fixed. +Total 30 packages affected by 92 known vulnerabilities (13 Critical, 29 High, 34 Medium, 6 Low, 10 Unknown) from 1 ecosystem. +41 vulnerabilities can be fixed. Ubuntu:22.04 @@ -608,14 +608,14 @@ Ubuntu:22.04 | gnupg2 | 2.2.27-3ubuntu2.1 | Partial fixes Available | 5 | gpgv | # 4 Layer | ubuntu | | gnutls28 | 3.7.3-4ubuntu1.5 | Fix Available | 4 | libgnutls30 | # 4 Layer | ubuntu | | gzip | 1.10-4ubuntu4.1 | Fix Available | 1 | gzip | # 4 Layer | ubuntu | -| krb5 | 1.19.2-2ubuntu0.4 | Partial fixes Available | 5 | libgssapi-krb5-2... (4) | # 4 Layer | ubuntu | +| krb5 | 1.19.2-2ubuntu0.4 | Fix Available | 3 | libgssapi-krb5-2... (4) | # 4 Layer | ubuntu | | libcap2 | 1:2.44-1ubuntu0.22.04.1 | Fix Available | 2 | libcap2 | # 4 Layer | ubuntu | | libgcrypt20 | 1.9.4-3ubuntu3 | Partial fixes Available | 2 | libgcrypt20 | # 4 Layer | ubuntu | | libtasn1-6 | 4.18.0-4build1 | Fix Available | 2 | libtasn1-6 | # 4 Layer | ubuntu | | libzstd | 1.4.8+dfsg-3build1 | No fix available | 1 | libzstd1 | # 4 Layer | ubuntu | | lz4 | 1.9.3-2build2 | No fix available | 1 | liblz4-1 | # 4 Layer | ubuntu | | ncurses | 6.3-2ubuntu0.1 | Partial fixes Available | 3 | libncurses6... (5) | # 4 Layer | ubuntu | -| openssl | 3.0.2-0ubuntu1.18 | Partial fixes Available | 7 | libssl3 | # 4 Layer | ubuntu | +| openssl | 3.0.2-0ubuntu1.18 | Fix Available | 5 | libssl3 | # 4 Layer | ubuntu | | p11-kit | 0.24.0-6build1 | No fix available | 1 | libp11-kit0 | # 4 Layer | ubuntu | | pam | 1.4.0-11ubuntu2.5 | Partial fixes Available | 3 | libpam-modules... (4) | # 4 Layer | ubuntu | | pcre2 | 10.39-3ubuntu0.1 | No fix available | 1 | libpcre2-8-0 | # 4 Layer | ubuntu | @@ -644,8 +644,8 @@ Scanning local image tarball "./testdata/test-java-full.tar" Container Scanning Result (Alpine Linux v3.21) (Based on "eclipse-temurin" image): -Total 39 packages affected by 159 known vulnerabilities (5 Critical, 74 High, 71 Medium, 8 Low, 1 Unknown) from 2 ecosystems. -159 vulnerabilities can be fixed. +Total 42 packages affected by 177 known vulnerabilities (5 Critical, 85 High, 78 Medium, 8 Low, 1 Unknown) from 2 ecosystems. +177 vulnerabilities can be fixed. Maven @@ -654,24 +654,26 @@ Maven +---------------------------------------------+-------------------+---------------+------------+------------------+---------------+ | PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE | +---------------------------------------------+-------------------+---------------+------------+------------------+---------------+ -| com.fasterxml.jackson.core:jackson-core | 2.10.2 | Fix Available | 3 | # 12 Layer | -- | +| com.fasterxml.jackson.core:jackson-core | 2.10.2 | Fix Available | 4 | # 12 Layer | -- | | com.fasterxml.jackson.core:jackson-databind | 2.12.7.1 | Fix Available | 5 | # 12 Layer | -- | | com.google.protobuf:protobuf-java | 3.21.12 | Fix Available | 1 | # 12 Layer | -- | | com.nimbusds:nimbus-jose-jwt | 9.31 | Fix Available | 2 | # 12 Layer | -- | | commons-beanutils:commons-beanutils | 1.9.4 | Fix Available | 1 | # 12 Layer | -- | | dnsjava:dnsjava | 3.4.0 | Fix Available | 1 | # 12 Layer | -- | -| io.netty:netty-codec | 4.1.100.Final | Fix Available | 2 | # 12 Layer | -- | +| io.netty:netty-codec | 4.1.100.Final | Fix Available | 3 | # 12 Layer | -- | | io.netty:netty-codec-dns | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | -| io.netty:netty-codec-haproxy | 4.1.100.Final | Fix Available | 2 | # 12 Layer | -- | -| io.netty:netty-codec-http | 4.1.100.Final | Fix Available | 11 | # 12 Layer | -- | -| io.netty:netty-codec-http2 | 4.1.100.Final | Fix Available | 6 | # 12 Layer | -- | +| io.netty:netty-codec-haproxy | 4.1.100.Final | Fix Available | 4 | # 12 Layer | -- | +| io.netty:netty-codec-http | 4.1.100.Final | Fix Available | 18 | # 12 Layer | -- | +| io.netty:netty-codec-http2 | 4.1.100.Final | Fix Available | 7 | # 12 Layer | -- | | io.netty:netty-codec-mqtt | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | | io.netty:netty-codec-redis | 4.1.100.Final | Fix Available | 5 | # 12 Layer | -- | | io.netty:netty-codec-smtp | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | -| io.netty:netty-codec-stomp | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | +| io.netty:netty-codec-stomp | 4.1.100.Final | Fix Available | 2 | # 12 Layer | -- | +| io.netty:netty-codec-xml | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | | io.netty:netty-common | 4.1.100.Final | Fix Available | 2 | # 12 Layer | -- | | io.netty:netty-handler | 4.1.100.Final | Fix Available | 4 | # 12 Layer | -- | | io.netty:netty-handler-proxy | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | +| io.netty:netty-handler-ssl-ocsp | 4.1.100.Final | Fix Available | 3 | # 12 Layer | -- | | io.netty:netty-resolver-dns | 4.1.100.Final | Fix Available | 3 | # 12 Layer | -- | | io.netty:netty-transport-native-epoll | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | | io.netty:netty-transport-native-kqueue | 4.1.100.Final | Fix Available | 1 | # 12 Layer | -- | @@ -681,6 +683,7 @@ Maven | org.apache.commons:commons-configuration2 | 2.8.0 | Fix Available | 3 | # 12 Layer | -- | | org.apache.commons:commons-lang3 | 3.12.0 | Fix Available | 1 | # 12 Layer | -- | | org.eclipse.jetty:jetty-http | 9.4.53.v20231009 | Fix Available | 3 | # 12 Layer | -- | +| org.eclipse.jetty:jetty-security | 9.4.53.v20231009 | Fix Available | 1 | # 12 Layer | -- | | org.jline:jline-remote-telnet | 3.9.0 | Fix Available | 2 | # 12 Layer | -- | +---------------------------------------------+-------------------+---------------+------------+------------------+---------------+ Alpine:v3.21 @@ -1425,6 +1428,7 @@ You can also view the full vulnerability list in your terminal with: `osv-scanne "PYSEC-2026-3447", "GHSA-5rjg-fvgr-3xxf", "GHSA-cx63-2mw6-8hw5", + "GHSA-h35f-9h28-mq5c", "GHSA-r9hx-vwmv-q579" ] } @@ -1621,6 +1625,7 @@ You can also view the full vulnerability list in your terminal with: `osv-scanne "PYSEC-2026-3447", "GHSA-5rjg-fvgr-3xxf", "GHSA-cx63-2mw6-8hw5", + "GHSA-h35f-9h28-mq5c", "GHSA-r9hx-vwmv-q579" ] } @@ -4127,9 +4132,10 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -4153,9 +4159,10 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -4179,9 +4186,10 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -4205,9 +4213,10 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -4455,7 +4464,7 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-8414-1", "USN-7980-1", @@ -4463,10 +4472,8 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "USN-7786-1", "USN-7278-1", "UBUNTU-CVE-2024-13176", - "UBUNTU-CVE-2024-41996", "UBUNTU-CVE-2024-9143", "UBUNTU-CVE-2025-15467", - "UBUNTU-CVE-2025-27587", "UBUNTU-CVE-2025-68160", "UBUNTU-CVE-2025-69418", "UBUNTU-CVE-2025-69419", @@ -4777,6 +4784,7 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar" "groups": 2, "vulnerabilities": [ "USN-8477-2", + "USN-8477-3", "USN-8510-1", "USN-8477-1", "UBUNTU-CVE-2025-45582", @@ -5365,9 +5373,10 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -5391,9 +5400,10 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -5417,9 +5427,10 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -5443,9 +5454,10 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-7314-1", + "USN-8585-1", "USN-7257-1", "USN-7542-1", "UBUNTU-CVE-2018-5709", @@ -5693,7 +5705,7 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "index": 4 } }, - "groups": 7, + "groups": 5, "vulnerabilities": [ "USN-8414-1", "USN-7980-1", @@ -5701,10 +5713,8 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "USN-7786-1", "USN-7278-1", "UBUNTU-CVE-2024-13176", - "UBUNTU-CVE-2024-41996", "UBUNTU-CVE-2024-9143", "UBUNTU-CVE-2025-15467", - "UBUNTU-CVE-2025-27587", "UBUNTU-CVE-2025-68160", "UBUNTU-CVE-2025-69418", "UBUNTU-CVE-2025-69419", @@ -6015,6 +6025,7 @@ Scanning local image tarball "./testdata/test-ubuntu.tar" "groups": 2, "vulnerabilities": [ "USN-8477-2", + "USN-8477-3", "USN-8510-1", "USN-8477-1", "UBUNTU-CVE-2025-45582", diff --git a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml index 4fbae364eaa..8aed5b679ca 100644 --- a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml +++ b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml @@ -637,7 +637,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -976,7 +976,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -1521,7 +1521,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 13082 + content_length: 13067 body: | { "results": [ @@ -1927,7 +1927,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2018-5709", - "modified": "2026-05-29T10:45:16.478625Z" + "modified": "2026-07-22T16:17:36.309424Z" }, { "id": "UBUNTU-CVE-2024-26458", @@ -1951,15 +1951,15 @@ interactions: }, { "id": "UBUNTU-CVE-2026-11850", - "modified": "2026-07-15T23:45:12.213127Z" + "modified": "2026-07-22T20:45:27.811204Z" }, { "id": "UBUNTU-CVE-2026-40355", - "modified": "2026-07-09T21:30:58.285031Z" + "modified": "2026-07-22T20:45:28.656761Z" }, { "id": "UBUNTU-CVE-2026-40356", - "modified": "2026-07-09T21:30:58.537034Z" + "modified": "2026-07-22T20:45:28.414538Z" }, { "id": "USN-7257-1", @@ -1972,6 +1972,10 @@ interactions: { "id": "USN-7542-1", "modified": "2026-06-25T13:32:30.616782Z" + }, + { + "id": "USN-8585-1", + "modified": "2026-07-22T20:59:37.292009Z" } ] }, @@ -2027,7 +2031,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2024-10041", - "modified": "2026-04-22T14:37:13.108514Z" + "modified": "2026-07-23T20:36:57.455980Z" }, { "id": "UBUNTU-CVE-2025-6020", @@ -2035,7 +2039,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-54411", - "modified": "2026-06-24T09:03:12Z" + "modified": "2026-07-23T20:40:45.157455Z" }, { "id": "USN-7580-1", @@ -2055,7 +2059,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -2070,10 +2074,6 @@ interactions: "id": "UBUNTU-CVE-2024-13176", "modified": "2026-06-16T13:30:37.035462Z" }, - { - "id": "UBUNTU-CVE-2024-41996", - "modified": "2026-07-08T22:45:14.910732Z" - }, { "id": "UBUNTU-CVE-2024-9143", "modified": "2026-06-16T13:30:42.533862Z" @@ -2082,10 +2082,6 @@ interactions: "id": "UBUNTU-CVE-2025-15467", "modified": "2026-07-20T16:16:27.574391Z" }, - { - "id": "UBUNTU-CVE-2025-27587", - "modified": "2026-06-16T13:30:42.231385Z" - }, { "id": "UBUNTU-CVE-2025-68160", "modified": "2026-07-08T22:45:11.201806Z" @@ -2391,11 +2387,11 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2025-45582", - "modified": "2026-07-17T01:21:14.776695Z" + "modified": "2026-07-22T20:46:40.337951Z" }, { "id": "UBUNTU-CVE-2026-5704", - "modified": "2026-07-17T01:29:55.319924Z" + "modified": "2026-07-22T20:59:36.824197Z" }, { "id": "USN-8477-1", @@ -2405,6 +2401,10 @@ interactions: "id": "USN-8477-2", "modified": "2026-07-17T05:19:51.333549Z" }, + { + "id": "USN-8477-3", + "modified": "2026-07-22T20:59:36.420470Z" + }, { "id": "USN-8510-1", "modified": "2026-07-06T20:34:34.654931Z" @@ -2418,7 +2418,7 @@ interactions: } headers: Content-Length: - - "13082" + - "13067" Content-Type: - application/json status: 200 OK @@ -2943,7 +2943,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 13082 + content_length: 13067 body: | { "results": [ @@ -3349,7 +3349,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2018-5709", - "modified": "2026-05-29T10:45:16.478625Z" + "modified": "2026-07-22T16:17:36.309424Z" }, { "id": "UBUNTU-CVE-2024-26458", @@ -3373,15 +3373,15 @@ interactions: }, { "id": "UBUNTU-CVE-2026-11850", - "modified": "2026-07-15T23:45:12.213127Z" + "modified": "2026-07-22T20:45:27.811204Z" }, { "id": "UBUNTU-CVE-2026-40355", - "modified": "2026-07-09T21:30:58.285031Z" + "modified": "2026-07-22T20:45:28.656761Z" }, { "id": "UBUNTU-CVE-2026-40356", - "modified": "2026-07-09T21:30:58.537034Z" + "modified": "2026-07-22T20:45:28.414538Z" }, { "id": "USN-7257-1", @@ -3394,6 +3394,10 @@ interactions: { "id": "USN-7542-1", "modified": "2026-06-25T13:32:30.616782Z" + }, + { + "id": "USN-8585-1", + "modified": "2026-07-22T20:59:37.292009Z" } ] }, @@ -3449,7 +3453,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2024-10041", - "modified": "2026-04-22T14:37:13.108514Z" + "modified": "2026-07-23T20:36:57.455980Z" }, { "id": "UBUNTU-CVE-2025-6020", @@ -3457,7 +3461,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-54411", - "modified": "2026-06-24T09:03:12Z" + "modified": "2026-07-23T20:40:45.157455Z" }, { "id": "USN-7580-1", @@ -3477,7 +3481,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -3492,10 +3496,6 @@ interactions: "id": "UBUNTU-CVE-2024-13176", "modified": "2026-06-16T13:30:37.035462Z" }, - { - "id": "UBUNTU-CVE-2024-41996", - "modified": "2026-07-08T22:45:14.910732Z" - }, { "id": "UBUNTU-CVE-2024-9143", "modified": "2026-06-16T13:30:42.533862Z" @@ -3504,10 +3504,6 @@ interactions: "id": "UBUNTU-CVE-2025-15467", "modified": "2026-07-20T16:16:27.574391Z" }, - { - "id": "UBUNTU-CVE-2025-27587", - "modified": "2026-06-16T13:30:42.231385Z" - }, { "id": "UBUNTU-CVE-2025-68160", "modified": "2026-07-08T22:45:11.201806Z" @@ -3813,11 +3809,11 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2025-45582", - "modified": "2026-07-17T01:21:14.776695Z" + "modified": "2026-07-22T20:46:40.337951Z" }, { "id": "UBUNTU-CVE-2026-5704", - "modified": "2026-07-17T01:29:55.319924Z" + "modified": "2026-07-22T20:59:36.824197Z" }, { "id": "USN-8477-1", @@ -3827,6 +3823,10 @@ interactions: "id": "USN-8477-2", "modified": "2026-07-17T05:19:51.333549Z" }, + { + "id": "USN-8477-3", + "modified": "2026-07-22T20:59:36.420470Z" + }, { "id": "USN-8510-1", "modified": "2026-07-06T20:34:34.654931Z" @@ -3840,7 +3840,7 @@ interactions: } headers: Content-Length: - - "13082" + - "13067" Content-Type: - application/json status: 200 OK @@ -4379,7 +4379,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 19704 + content_length: 19689 body: | { "results": [ @@ -4634,7 +4634,7 @@ interactions: }, { "id": "GO-2023-2102", - "modified": "2026-04-16T11:14:10.849204Z" + "modified": "2026-07-23T14:14:36.488788Z" }, { "id": "GO-2023-2185", @@ -4734,7 +4734,7 @@ interactions: }, { "id": "GO-2025-3956", - "modified": "2026-02-04T04:33:27.340869Z" + "modified": "2026-07-23T14:14:36.609580Z" }, { "id": "GO-2025-4006", @@ -4770,7 +4770,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-06-26T12:29:46.364453Z" + "modified": "2026-07-23T14:14:36.403566Z" }, { "id": "GO-2025-4015", @@ -4778,7 +4778,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-07-17T10:29:28.826194Z" + "modified": "2026-07-23T14:14:36.334594Z" }, { "id": "GO-2025-4175", @@ -4786,7 +4786,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-07-07T10:29:23.547454Z" + "modified": "2026-07-23T14:14:36.084142Z" }, { "id": "GO-2026-4340", @@ -4794,11 +4794,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-07-16T10:29:36.442242Z" + "modified": "2026-07-23T14:14:36.006729Z" }, { "id": "GO-2026-4342", - "modified": "2026-07-02T10:44:29.686144Z" + "modified": "2026-07-23T14:14:36.153870Z" }, { "id": "GO-2026-4403", @@ -4806,7 +4806,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-07-17T10:29:28.643038Z" + "modified": "2026-07-23T14:14:36.223456Z" }, { "id": "GO-2026-4602", @@ -4838,7 +4838,7 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-07-17T10:29:27.777936Z" + "modified": "2026-07-23T10:44:38.430505Z" }, { "id": "GO-2026-4947", @@ -4866,7 +4866,7 @@ interactions: }, { "id": "GO-2026-4981", - "modified": "2026-07-17T10:29:28.049309Z" + "modified": "2026-07-23T10:44:38.713700Z" }, { "id": "GO-2026-4982", @@ -4878,7 +4878,7 @@ interactions: }, { "id": "GO-2026-5037", - "modified": "2026-07-16T10:29:37.326923Z" + "modified": "2026-07-23T10:44:38.638231Z" }, { "id": "GO-2026-5038", @@ -5217,7 +5217,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2018-5709", - "modified": "2026-05-29T10:45:16.478625Z" + "modified": "2026-07-22T16:17:36.309424Z" }, { "id": "UBUNTU-CVE-2024-26458", @@ -5241,15 +5241,15 @@ interactions: }, { "id": "UBUNTU-CVE-2026-11850", - "modified": "2026-07-15T23:45:12.213127Z" + "modified": "2026-07-22T20:45:27.811204Z" }, { "id": "UBUNTU-CVE-2026-40355", - "modified": "2026-07-09T21:30:58.285031Z" + "modified": "2026-07-22T20:45:28.656761Z" }, { "id": "UBUNTU-CVE-2026-40356", - "modified": "2026-07-09T21:30:58.537034Z" + "modified": "2026-07-22T20:45:28.414538Z" }, { "id": "USN-7257-1", @@ -5262,6 +5262,10 @@ interactions: { "id": "USN-7542-1", "modified": "2026-06-25T13:32:30.616782Z" + }, + { + "id": "USN-8585-1", + "modified": "2026-07-22T20:59:37.292009Z" } ] }, @@ -5317,7 +5321,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2024-10041", - "modified": "2026-04-22T14:37:13.108514Z" + "modified": "2026-07-23T20:36:57.455980Z" }, { "id": "UBUNTU-CVE-2025-6020", @@ -5325,7 +5329,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-54411", - "modified": "2026-06-24T09:03:12Z" + "modified": "2026-07-23T20:40:45.157455Z" }, { "id": "USN-7580-1", @@ -5345,7 +5349,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -5360,10 +5364,6 @@ interactions: "id": "UBUNTU-CVE-2024-13176", "modified": "2026-06-16T13:30:37.035462Z" }, - { - "id": "UBUNTU-CVE-2024-41996", - "modified": "2026-07-08T22:45:14.910732Z" - }, { "id": "UBUNTU-CVE-2024-9143", "modified": "2026-06-16T13:30:42.533862Z" @@ -5372,10 +5372,6 @@ interactions: "id": "UBUNTU-CVE-2025-15467", "modified": "2026-07-20T16:16:27.574391Z" }, - { - "id": "UBUNTU-CVE-2025-27587", - "modified": "2026-06-16T13:30:42.231385Z" - }, { "id": "UBUNTU-CVE-2025-68160", "modified": "2026-07-08T22:45:11.201806Z" @@ -5681,11 +5677,11 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2025-45582", - "modified": "2026-07-17T01:21:14.776695Z" + "modified": "2026-07-22T20:46:40.337951Z" }, { "id": "UBUNTU-CVE-2026-5704", - "modified": "2026-07-17T01:29:55.319924Z" + "modified": "2026-07-22T20:59:36.824197Z" }, { "id": "USN-8477-1", @@ -5695,6 +5691,10 @@ interactions: "id": "USN-8477-2", "modified": "2026-07-17T05:19:51.333549Z" }, + { + "id": "USN-8477-3", + "modified": "2026-07-22T20:59:36.420470Z" + }, { "id": "USN-8510-1", "modified": "2026-07-06T20:34:34.654931Z" @@ -5708,7 +5708,7 @@ interactions: } headers: Content-Length: - - "19704" + - "19689" Content-Type: - application/json status: 200 OK @@ -7003,7 +7003,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 12199 + content_length: 13486 body: | { "results": [ @@ -7038,6 +7038,10 @@ interactions: "id": "GHSA-h46c-h94j-95f3", "modified": "2026-02-04T03:44:39.385253Z" }, + { + "id": "GHSA-r7wm-3cxj-wff9", + "modified": "2026-07-22T20:59:38.595267Z" + }, { "id": "GHSA-wf8f-6423-gfxg", "modified": "2026-02-04T02:17:21.257294Z" @@ -7064,7 +7068,7 @@ interactions: }, { "id": "GHSA-rmj7-2vxq-3g9f", - "modified": "2026-07-20T21:30:42.835792Z" + "modified": "2026-07-23T12:46:21.393820Z" } ] }, @@ -7242,6 +7246,10 @@ interactions: "id": "GHSA-3p8m-j85q-pgmj", "modified": "2026-02-04T02:23:33.973208Z" }, + { + "id": "GHSA-558v-64gr-wgg4", + "modified": "2026-07-22T22:00:25.847691Z" + }, { "id": "GHSA-mj4r-2hfc-f8p6", "modified": "2026-05-14T20:52:02.730912Z" @@ -7264,7 +7272,15 @@ interactions: }, { "id": "GHSA-h2qv-fj59-j46j", - "modified": "2026-07-10T12:45:24.288759Z" + "modified": "2026-07-21T12:46:29.754499Z" + }, + { + "id": "GHSA-q6cq-mhr2-jmr5", + "modified": "2026-07-22T21:30:28.538600Z" + }, + { + "id": "GHSA-wh89-7897-x99h", + "modified": "2026-07-22T22:00:25.805753Z" } ] }, @@ -7274,6 +7290,10 @@ interactions: "id": "GHSA-38f8-5428-x5cv", "modified": "2026-05-14T20:48:37.405742Z" }, + { + "id": "GHSA-4mp9-239f-g9hg", + "modified": "2026-07-22T22:00:25.837295Z" + }, { "id": "GHSA-57rv-r2g8-2cj3", "modified": "2026-05-14T20:47:30.693204Z" @@ -7282,6 +7302,14 @@ interactions: "id": "GHSA-5jpm-x58v-624v", "modified": "2026-02-04T02:17:39.757688Z" }, + { + "id": "GHSA-6cqp-g7gg-8hr5", + "modified": "2026-07-22T21:46:10.912549Z" + }, + { + "id": "GHSA-6jqx-86gh-f27w", + "modified": "2026-07-22T21:15:32.599992Z" + }, { "id": "GHSA-84h7-rjj3-6jx4", "modified": "2026-02-04T03:25:14.697311Z" @@ -7294,18 +7322,34 @@ interactions: "id": "GHSA-fghv-69vj-qj49", "modified": "2026-02-04T03:04:04.888405Z" }, + { + "id": "GHSA-gcjf-9mgh-3p7g", + "modified": "2026-07-22T22:00:25.808021Z" + }, { "id": "GHSA-hvcg-qmg6-jm4c", "modified": "2026-06-16T14:44:20.815695Z" }, + { + "id": "GHSA-jppx-w49h-x2qq", + "modified": "2026-07-22T21:46:10.971835Z" + }, { "id": "GHSA-m4cv-j2px-7723", "modified": "2026-05-14T20:52:01.053039Z" }, + { + "id": "GHSA-mvh2-crg5-v77c", + "modified": "2026-07-22T21:30:28.556773Z" + }, { "id": "GHSA-pwqr-wmgm-9rr8", "modified": "2026-03-27T22:04:14.372867Z" }, + { + "id": "GHSA-q4f6-jm68-57ww", + "modified": "2026-07-22T22:00:25.800321Z" + }, { "id": "GHSA-v8h7-rr48-vmmv", "modified": "2026-05-08T19:50:55.560203Z" @@ -7328,7 +7372,11 @@ interactions: }, { "id": "GHSA-c2gf-v879-257j", - "modified": "2026-07-10T12:45:24.320409Z" + "modified": "2026-07-21T12:46:28.160944Z" + }, + { + "id": "GHSA-c69g-56f8-xwqj", + "modified": "2026-07-22T22:00:27.110008Z" }, { "id": "GHSA-f6hv-jmp6-3vwv", @@ -7369,7 +7417,7 @@ interactions: }, { "id": "GHSA-6jv9-x5w9-2ccm", - "modified": "2026-07-10T12:45:25.759557Z" + "modified": "2026-07-21T12:46:28.207660Z" }, { "id": "GHSA-rgrr-p7gp-5xj7", @@ -7388,13 +7436,24 @@ interactions: {}, { "vulns": [ + { + "id": "GHSA-3g8r-4pfx-jmfh", + "modified": "2026-07-22T22:00:25.851657Z" + }, { "id": "GHSA-vhch-2wf3-m8rp", "modified": "2026-07-15T18:29:41.887402Z" } ] }, - {}, + { + "vulns": [ + { + "id": "GHSA-4qhr-g3c6-fcfx", + "modified": "2026-07-22T21:46:10.924585Z" + } + ] + }, { "vulns": [ { @@ -7435,17 +7494,32 @@ interactions: } ] }, - {}, + { + "vulns": [ + { + "id": "GHSA-272m-gcwp-mpwg", + "modified": "2026-07-22T21:46:10.976177Z" + }, + { + "id": "GHSA-g7hg-vrcf-mvmr", + "modified": "2026-07-22T22:00:25.780409Z" + }, + { + "id": "GHSA-wc96-39fc-566f", + "modified": "2026-07-22T22:00:25.784688Z" + } + ] + }, {}, { "vulns": [ { "id": "GHSA-5pvg-856g-cp85", - "modified": "2026-07-10T12:45:25.665872Z" + "modified": "2026-07-21T12:46:28.166860Z" }, { "id": "GHSA-676x-f7gg-47vc", - "modified": "2026-07-10T12:45:25.760302Z" + "modified": "2026-07-21T12:46:28.167598Z" }, { "id": "GHSA-xmv7-r254-6q78", @@ -7866,7 +7940,14 @@ interactions: ] }, {}, - {}, + { + "vulns": [ + { + "id": "GHSA-2fvj-hgj9-j2gr", + "modified": "2026-07-22T23:01:08.283351Z" + } + ] + }, {}, {}, {}, @@ -7881,11 +7962,11 @@ interactions: "vulns": [ { "id": "GHSA-2r2c-cx56-8933", - "modified": "2026-07-20T21:30:36.917644Z" + "modified": "2026-07-21T14:59:37.751566Z" }, { "id": "GHSA-47qp-hqvx-6r3f", - "modified": "2026-07-20T21:30:39.763738Z" + "modified": "2026-07-21T14:59:37.539426Z" } ] }, @@ -7945,7 +8026,7 @@ interactions: } headers: Content-Length: - - "12199" + - "13486" Content-Type: - application/json status: 200 OK @@ -8463,7 +8544,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 2617 + content_length: 2687 body: | { "results": [ @@ -8660,6 +8741,10 @@ interactions: "id": "GHSA-cx63-2mw6-8hw5", "modified": "2026-07-07T17:57:13.326243Z" }, + { + "id": "GHSA-h35f-9h28-mq5c", + "modified": "2026-07-23T09:29:39.408842Z" + }, { "id": "GHSA-r9hx-vwmv-q579", "modified": "2026-02-04T03:03:25.892107Z" @@ -8720,7 +8805,7 @@ interactions: } headers: Content-Length: - - "2617" + - "2687" Content-Type: - application/json status: 200 OK @@ -9329,7 +9414,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 6247 + content_length: 6317 body: | { "results": [ @@ -9692,6 +9777,10 @@ interactions: "id": "GHSA-cx63-2mw6-8hw5", "modified": "2026-07-07T17:57:13.326243Z" }, + { + "id": "GHSA-h35f-9h28-mq5c", + "modified": "2026-07-23T09:29:39.408842Z" + }, { "id": "GHSA-r9hx-vwmv-q579", "modified": "2026-02-04T03:03:25.892107Z" @@ -9828,7 +9917,7 @@ interactions: } headers: Content-Length: - - "6247" + - "6317" Content-Type: - application/json status: 200 OK @@ -10029,7 +10118,7 @@ interactions: }, { "id": "GO-2025-3956", - "modified": "2026-02-04T04:33:27.340869Z" + "modified": "2026-07-23T14:14:36.609580Z" }, { "id": "GO-2025-4006", @@ -10065,7 +10154,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-06-26T12:29:46.364453Z" + "modified": "2026-07-23T14:14:36.403566Z" }, { "id": "GO-2025-4015", @@ -10073,7 +10162,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-07-17T10:29:28.826194Z" + "modified": "2026-07-23T14:14:36.334594Z" }, { "id": "GO-2025-4175", @@ -10081,7 +10170,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-07-07T10:29:23.547454Z" + "modified": "2026-07-23T14:14:36.084142Z" }, { "id": "GO-2026-4340", @@ -10089,11 +10178,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-07-16T10:29:36.442242Z" + "modified": "2026-07-23T14:14:36.006729Z" }, { "id": "GO-2026-4342", - "modified": "2026-07-02T10:44:29.686144Z" + "modified": "2026-07-23T14:14:36.153870Z" }, { "id": "GO-2026-4403", @@ -10101,7 +10190,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-07-17T10:29:28.643038Z" + "modified": "2026-07-23T14:14:36.223456Z" }, { "id": "GO-2026-4602", @@ -10133,7 +10222,7 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-07-17T10:29:27.777936Z" + "modified": "2026-07-23T10:44:38.430505Z" }, { "id": "GO-2026-4947", @@ -10161,7 +10250,7 @@ interactions: }, { "id": "GO-2026-4981", - "modified": "2026-07-17T10:29:28.049309Z" + "modified": "2026-07-23T10:44:38.713700Z" }, { "id": "GO-2026-4982", @@ -10173,7 +10262,7 @@ interactions: }, { "id": "GO-2026-5037", - "modified": "2026-07-16T10:29:37.326923Z" + "modified": "2026-07-23T10:44:38.638231Z" }, { "id": "GO-2026-5038", @@ -11093,7 +11182,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-07-17T10:29:28.643038Z" + "modified": "2026-07-23T14:14:36.223456Z" }, { "id": "GO-2026-4602", @@ -11129,7 +11218,7 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-07-17T10:29:27.777936Z" + "modified": "2026-07-23T10:44:38.430505Z" }, { "id": "GO-2026-4947", @@ -11157,7 +11246,7 @@ interactions: }, { "id": "GO-2026-4981", - "modified": "2026-07-17T10:29:28.049309Z" + "modified": "2026-07-23T10:44:38.713700Z" }, { "id": "GO-2026-4982", @@ -11169,7 +11258,7 @@ interactions: }, { "id": "GO-2026-5037", - "modified": "2026-07-16T10:29:37.326923Z" + "modified": "2026-07-23T10:44:38.638231Z" }, { "id": "GO-2026-5038", diff --git a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml index b91f3631489..638910a28e8 100644 --- a/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml +++ b/cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml @@ -604,7 +604,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 6247 + content_length: 6317 body: | { "results": [ @@ -967,6 +967,10 @@ interactions: "id": "GHSA-cx63-2mw6-8hw5", "modified": "2026-07-07T17:57:13.326243Z" }, + { + "id": "GHSA-h35f-9h28-mq5c", + "modified": "2026-07-23T09:29:39.408842Z" + }, { "id": "GHSA-r9hx-vwmv-q579", "modified": "2026-02-04T03:03:25.892107Z" @@ -1103,7 +1107,7 @@ interactions: } headers: Content-Length: - - "6247" + - "6317" Content-Type: - application/json status: 200 OK @@ -1580,7 +1584,7 @@ interactions: }, { "id": "ALPINE-CVE-2026-42770", - "modified": "2026-07-08T04:32:29.279599Z" + "modified": "2026-07-21T08:45:05.642165Z" }, { "id": "ALPINE-CVE-2026-45445", @@ -1840,7 +1844,7 @@ interactions: }, { "id": "GO-2025-3956", - "modified": "2026-02-04T04:33:27.340869Z" + "modified": "2026-07-23T14:14:36.609580Z" }, { "id": "GO-2025-4006", @@ -1876,7 +1880,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-06-26T12:29:46.364453Z" + "modified": "2026-07-23T14:14:36.403566Z" }, { "id": "GO-2025-4015", @@ -1884,7 +1888,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-07-17T10:29:28.826194Z" + "modified": "2026-07-23T14:14:36.334594Z" }, { "id": "GO-2025-4175", @@ -1892,7 +1896,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-07-07T10:29:23.547454Z" + "modified": "2026-07-23T14:14:36.084142Z" }, { "id": "GO-2026-4340", @@ -1900,11 +1904,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-07-16T10:29:36.442242Z" + "modified": "2026-07-23T14:14:36.006729Z" }, { "id": "GO-2026-4342", - "modified": "2026-07-02T10:44:29.686144Z" + "modified": "2026-07-23T14:14:36.153870Z" }, { "id": "GO-2026-4403", @@ -1912,7 +1916,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-07-17T10:29:28.643038Z" + "modified": "2026-07-23T14:14:36.223456Z" }, { "id": "GO-2026-4602", @@ -1944,7 +1948,7 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-07-17T10:29:27.777936Z" + "modified": "2026-07-23T10:44:38.430505Z" }, { "id": "GO-2026-4947", @@ -1972,7 +1976,7 @@ interactions: }, { "id": "GO-2026-4981", - "modified": "2026-07-17T10:29:28.049309Z" + "modified": "2026-07-23T10:44:38.713700Z" }, { "id": "GO-2026-4982", @@ -1984,7 +1988,7 @@ interactions: }, { "id": "GO-2026-5037", - "modified": "2026-07-16T10:29:37.326923Z" + "modified": "2026-07-23T10:44:38.638231Z" }, { "id": "GO-2026-5038", @@ -2642,7 +2646,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-07-17T10:29:28.643038Z" + "modified": "2026-07-23T14:14:36.223456Z" }, { "id": "GO-2026-4602", @@ -2678,7 +2682,7 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-07-17T10:29:27.777936Z" + "modified": "2026-07-23T10:44:38.430505Z" }, { "id": "GO-2026-4947", @@ -2706,7 +2710,7 @@ interactions: }, { "id": "GO-2026-4981", - "modified": "2026-07-17T10:29:28.049309Z" + "modified": "2026-07-23T10:44:38.713700Z" }, { "id": "GO-2026-4982", @@ -2718,7 +2722,7 @@ interactions: }, { "id": "GO-2026-5037", - "modified": "2026-07-16T10:29:37.326923Z" + "modified": "2026-07-23T10:44:38.638231Z" }, { "id": "GO-2026-5038", @@ -3530,7 +3534,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 13082 + content_length: 13067 body: | { "results": [ @@ -3936,7 +3940,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2018-5709", - "modified": "2026-05-29T10:45:16.478625Z" + "modified": "2026-07-22T16:17:36.309424Z" }, { "id": "UBUNTU-CVE-2024-26458", @@ -3960,15 +3964,15 @@ interactions: }, { "id": "UBUNTU-CVE-2026-11850", - "modified": "2026-07-15T23:45:12.213127Z" + "modified": "2026-07-22T20:45:27.811204Z" }, { "id": "UBUNTU-CVE-2026-40355", - "modified": "2026-07-09T21:30:58.285031Z" + "modified": "2026-07-22T20:45:28.656761Z" }, { "id": "UBUNTU-CVE-2026-40356", - "modified": "2026-07-09T21:30:58.537034Z" + "modified": "2026-07-22T20:45:28.414538Z" }, { "id": "USN-7257-1", @@ -3981,6 +3985,10 @@ interactions: { "id": "USN-7542-1", "modified": "2026-06-25T13:32:30.616782Z" + }, + { + "id": "USN-8585-1", + "modified": "2026-07-22T20:59:37.292009Z" } ] }, @@ -4036,7 +4044,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2024-10041", - "modified": "2026-04-22T14:37:13.108514Z" + "modified": "2026-07-23T20:36:57.455980Z" }, { "id": "UBUNTU-CVE-2025-6020", @@ -4044,7 +4052,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-54411", - "modified": "2026-06-24T09:03:12Z" + "modified": "2026-07-23T20:40:45.157455Z" }, { "id": "USN-7580-1", @@ -4064,7 +4072,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -4079,10 +4087,6 @@ interactions: "id": "UBUNTU-CVE-2024-13176", "modified": "2026-06-16T13:30:37.035462Z" }, - { - "id": "UBUNTU-CVE-2024-41996", - "modified": "2026-07-08T22:45:14.910732Z" - }, { "id": "UBUNTU-CVE-2024-9143", "modified": "2026-06-16T13:30:42.533862Z" @@ -4091,10 +4095,6 @@ interactions: "id": "UBUNTU-CVE-2025-15467", "modified": "2026-07-20T16:16:27.574391Z" }, - { - "id": "UBUNTU-CVE-2025-27587", - "modified": "2026-06-16T13:30:42.231385Z" - }, { "id": "UBUNTU-CVE-2025-68160", "modified": "2026-07-08T22:45:11.201806Z" @@ -4400,11 +4400,11 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2025-45582", - "modified": "2026-07-17T01:21:14.776695Z" + "modified": "2026-07-22T20:46:40.337951Z" }, { "id": "UBUNTU-CVE-2026-5704", - "modified": "2026-07-17T01:29:55.319924Z" + "modified": "2026-07-22T20:59:36.824197Z" }, { "id": "USN-8477-1", @@ -4414,6 +4414,10 @@ interactions: "id": "USN-8477-2", "modified": "2026-07-17T05:19:51.333549Z" }, + { + "id": "USN-8477-3", + "modified": "2026-07-22T20:59:36.420470Z" + }, { "id": "USN-8510-1", "modified": "2026-07-06T20:34:34.654931Z" @@ -4427,7 +4431,7 @@ interactions: } headers: Content-Length: - - "13082" + - "13067" Content-Type: - application/json status: 200 OK @@ -4966,7 +4970,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 19704 + content_length: 19689 body: | { "results": [ @@ -5221,7 +5225,7 @@ interactions: }, { "id": "GO-2023-2102", - "modified": "2026-04-16T11:14:10.849204Z" + "modified": "2026-07-23T14:14:36.488788Z" }, { "id": "GO-2023-2185", @@ -5321,7 +5325,7 @@ interactions: }, { "id": "GO-2025-3956", - "modified": "2026-02-04T04:33:27.340869Z" + "modified": "2026-07-23T14:14:36.609580Z" }, { "id": "GO-2025-4006", @@ -5357,7 +5361,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-06-26T12:29:46.364453Z" + "modified": "2026-07-23T14:14:36.403566Z" }, { "id": "GO-2025-4015", @@ -5365,7 +5369,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-07-17T10:29:28.826194Z" + "modified": "2026-07-23T14:14:36.334594Z" }, { "id": "GO-2025-4175", @@ -5373,7 +5377,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-07-07T10:29:23.547454Z" + "modified": "2026-07-23T14:14:36.084142Z" }, { "id": "GO-2026-4340", @@ -5381,11 +5385,11 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-07-16T10:29:36.442242Z" + "modified": "2026-07-23T14:14:36.006729Z" }, { "id": "GO-2026-4342", - "modified": "2026-07-02T10:44:29.686144Z" + "modified": "2026-07-23T14:14:36.153870Z" }, { "id": "GO-2026-4403", @@ -5393,7 +5397,7 @@ interactions: }, { "id": "GO-2026-4601", - "modified": "2026-07-17T10:29:28.643038Z" + "modified": "2026-07-23T14:14:36.223456Z" }, { "id": "GO-2026-4602", @@ -5425,7 +5429,7 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-07-17T10:29:27.777936Z" + "modified": "2026-07-23T10:44:38.430505Z" }, { "id": "GO-2026-4947", @@ -5453,7 +5457,7 @@ interactions: }, { "id": "GO-2026-4981", - "modified": "2026-07-17T10:29:28.049309Z" + "modified": "2026-07-23T10:44:38.713700Z" }, { "id": "GO-2026-4982", @@ -5465,7 +5469,7 @@ interactions: }, { "id": "GO-2026-5037", - "modified": "2026-07-16T10:29:37.326923Z" + "modified": "2026-07-23T10:44:38.638231Z" }, { "id": "GO-2026-5038", @@ -5804,7 +5808,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2018-5709", - "modified": "2026-05-29T10:45:16.478625Z" + "modified": "2026-07-22T16:17:36.309424Z" }, { "id": "UBUNTU-CVE-2024-26458", @@ -5828,15 +5832,15 @@ interactions: }, { "id": "UBUNTU-CVE-2026-11850", - "modified": "2026-07-15T23:45:12.213127Z" + "modified": "2026-07-22T20:45:27.811204Z" }, { "id": "UBUNTU-CVE-2026-40355", - "modified": "2026-07-09T21:30:58.285031Z" + "modified": "2026-07-22T20:45:28.656761Z" }, { "id": "UBUNTU-CVE-2026-40356", - "modified": "2026-07-09T21:30:58.537034Z" + "modified": "2026-07-22T20:45:28.414538Z" }, { "id": "USN-7257-1", @@ -5849,6 +5853,10 @@ interactions: { "id": "USN-7542-1", "modified": "2026-06-25T13:32:30.616782Z" + }, + { + "id": "USN-8585-1", + "modified": "2026-07-22T20:59:37.292009Z" } ] }, @@ -5904,7 +5912,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2024-10041", - "modified": "2026-04-22T14:37:13.108514Z" + "modified": "2026-07-23T20:36:57.455980Z" }, { "id": "UBUNTU-CVE-2025-6020", @@ -5912,7 +5920,7 @@ interactions: }, { "id": "UBUNTU-CVE-2026-54411", - "modified": "2026-06-24T09:03:12Z" + "modified": "2026-07-23T20:40:45.157455Z" }, { "id": "USN-7580-1", @@ -5932,7 +5940,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -5947,10 +5955,6 @@ interactions: "id": "UBUNTU-CVE-2024-13176", "modified": "2026-06-16T13:30:37.035462Z" }, - { - "id": "UBUNTU-CVE-2024-41996", - "modified": "2026-07-08T22:45:14.910732Z" - }, { "id": "UBUNTU-CVE-2024-9143", "modified": "2026-06-16T13:30:42.533862Z" @@ -5959,10 +5963,6 @@ interactions: "id": "UBUNTU-CVE-2025-15467", "modified": "2026-07-20T16:16:27.574391Z" }, - { - "id": "UBUNTU-CVE-2025-27587", - "modified": "2026-06-16T13:30:42.231385Z" - }, { "id": "UBUNTU-CVE-2025-68160", "modified": "2026-07-08T22:45:11.201806Z" @@ -6268,11 +6268,11 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2025-45582", - "modified": "2026-07-17T01:21:14.776695Z" + "modified": "2026-07-22T20:46:40.337951Z" }, { "id": "UBUNTU-CVE-2026-5704", - "modified": "2026-07-17T01:29:55.319924Z" + "modified": "2026-07-22T20:59:36.824197Z" }, { "id": "USN-8477-1", @@ -6282,6 +6282,10 @@ interactions: "id": "USN-8477-2", "modified": "2026-07-17T05:19:51.333549Z" }, + { + "id": "USN-8477-3", + "modified": "2026-07-22T20:59:36.420470Z" + }, { "id": "USN-8510-1", "modified": "2026-07-06T20:34:34.654931Z" @@ -6295,7 +6299,7 @@ interactions: } headers: Content-Length: - - "19704" + - "19689" Content-Type: - application/json status: 200 OK diff --git a/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap b/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap index 978c67d723e..cf99a642eda 100755 --- a/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap +++ b/cmd/osv-scanner/scan/source/__snapshots__/command_test.snap @@ -1123,7 +1123,7 @@ Scanned /testdata/sbom-insecure/postgres-stretch.cdx.xml file and found Scanned /testdata/sbom-insecure/with-duplicates.cdx.xml file and found 17 packages Filtered 10 local/unscannable package/s from the scan. -Total 27 packages affected by 233 known vulnerabilities (29 Critical, 99 High, 71 Medium, 6 Low, 28 Unknown) from 5 ecosystems. +Total 28 packages affected by 234 known vulnerabilities (29 Critical, 99 High, 71 Medium, 7 Low, 28 Unknown) from 5 ecosystems. 22 vulnerabilities can be fixed. +---------------------------------------+------+--------------+--------------------------------+------------------------------------+-----------------------------------+---------------------------------------------------------------------+ @@ -1171,6 +1171,7 @@ Total 27 packages affected by 233 known vulnerabilities (29 Critical, 99 High, 7 | https://osv.dev/DEBIAN-CVE-2016-2781 | 6.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2024-0684 | 5.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3482-1 | | Debian | debian-archive-keyring | 2017.5+deb9u2 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-53910 | 2.1 | Debian | diffutils | 1:3.5-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5147-1 | 9.8 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-6297 | 8.2 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2026-2219 | 7.5 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -2455,7 +2456,7 @@ Filtered 8 vulnerabilities from output testdata/osv-scanner-partial-ignores-config.toml has unused ignores: - CVE-2019-5188 -Total 25 packages affected by 227 known vulnerabilities (29 Critical, 94 High, 70 Medium, 6 Low, 28 Unknown) from 5 ecosystems. +Total 26 packages affected by 228 known vulnerabilities (29 Critical, 94 High, 70 Medium, 7 Low, 28 Unknown) from 5 ecosystems. 17 vulnerabilities can be fixed. +---------------------------------------+------+--------------+--------------------------------+------------------------------------+-----------------------------------+---------------------------------------------------------------------+ @@ -2497,6 +2498,7 @@ Total 25 packages affected by 227 known vulnerabilities (29 Critical, 94 High, 7 | https://osv.dev/DEBIAN-CVE-2016-2781 | 6.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2024-0684 | 5.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3482-1 | | Debian | debian-archive-keyring | 2017.5+deb9u2 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-53910 | 2.1 | Debian | diffutils | 1:3.5-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5147-1 | 9.8 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-6297 | 8.2 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2026-2219 | 7.5 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -2738,7 +2740,7 @@ Filtered 6 vulnerabilities from output testdata/osv-scanner-partial-ignores-config.toml has unused ignores: - CVE-2019-5188 -Total 23 packages affected by 223 known vulnerabilities (27 Critical, 93 High, 69 Medium, 6 Low, 28 Unknown) from 3 ecosystems. +Total 24 packages affected by 224 known vulnerabilities (27 Critical, 93 High, 69 Medium, 7 Low, 28 Unknown) from 3 ecosystems. 13 vulnerabilities can be fixed. +---------------------------------------+------+--------------+--------------------------------+------------------------------------+-----------------------------------+-------------------------------------------------+ @@ -2776,6 +2778,7 @@ Total 23 packages affected by 223 known vulnerabilities (27 Critical, 93 High, 6 | https://osv.dev/DEBIAN-CVE-2016-2781 | 6.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2024-0684 | 5.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3482-1 | | Debian | debian-archive-keyring | 2017.5+deb9u2 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-53910 | 2.1 | Debian | diffutils | 1:3.5-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5147-1 | 9.8 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-6297 | 8.2 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2026-2219 | 7.5 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -3950,18 +3953,22 @@ HTML output available at: /report.html [TestCommand_JavareachArchive/jars_can_be_scanned_with_call_analysis - 1] Scanning dir ./testdata/artifact/javareach_test.jar -Java reachability enricher marked 14 packages as unreachable +Java reachability enricher marked 21 packages as unreachable Scanned /testdata/artifact/javareach_test.jar file and found 21 packages -failed to download package err jar not found: https://repo1.maven.org/maven2/com/example/hello-tester/1.0-SNAPSHOT/hello-tester-1.0-SNAPSHOT.jar +failed to download package err jar not found: https://repo1.maven.org/maven2/com/amazonaws/jmespath-java/1.11.327/jmespath-java-1.11.327.jar -Total 4 packages affected by 57 known vulnerabilities (18 Critical, 30 High, 7 Medium, 2 Low, 0 Unknown) from 1 ecosystem. -57 vulnerabilities can be fixed. +Total 0 packages affected by 0 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 0 Unknown) from 1 ecosystem. +0 vulnerabilities can be fixed. +-------------------------------------+------+-----------+---------------------------------------------+------------------+---------------+--------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | +-------------------------------------+------+-----------+---------------------------------------------+------------------+---------------+--------------------------------------+ +| Uncalled vulnerabilities | | | | | | | ++-------------------------------------+------+-----------+---------------------------------------------+------------------+---------------+--------------------------------------+ +| https://osv.dev/GHSA-c28r-hw5m-5gv3 | 7.9 | Maven | com.amazonaws:aws-java-sdk-s3 | 1.11.327 | 1.12.261 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-72hv-8253-57qq | 6.9 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.18.6 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-h46c-h94j-95f3 | 8.7 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.15.0 | testdata/artifact/javareach_test.jar | +| https://osv.dev/GHSA-r7wm-3cxj-wff9 | 8.7 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.18.8 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-288c-cq4h-88gq | 7.5 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.6.7.4 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-4gq5-ch57-c2mg | 9.8 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.7.9.5 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-4w82-r329-3q67 | 9.8 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.6.7.4 | testdata/artifact/javareach_test.jar | @@ -4012,16 +4019,12 @@ Total 4 packages affected by 57 known vulnerabilities (18 Critical, 30 High, 7 M | https://osv.dev/GHSA-w3f4-3q6j-rh82 | 8.1 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.7.9.5 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-wh8g-3j2c-rqj5 | 8.1 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.9.10.8 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-j288-q9x7-2f5v | 6.5 | Maven | org.apache.commons:commons-lang3 | 3.12.0 | 3.18.0 | testdata/artifact/javareach_test.jar | +| https://osv.dev/GHSA-7r82-7xv7-xcpj | 5.3 | Maven | org.apache.httpcomponents:httpclient | 4.5.5 | 4.5.13 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-355h-qmc2-wpwf | 7.4 | Maven | org.eclipse.jetty:jetty-http | 9.4.40.v20210413 | 12.0.33 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-cj7v-27pg-wf7q | 2.7 | Maven | org.eclipse.jetty:jetty-http | 9.4.40.v20210413 | 9.4.47 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-hmr7-m48g-48f6 | 5.3 | Maven | org.eclipse.jetty:jetty-http | 9.4.40.v20210413 | 9.4.52 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-qh8g-58pp-2wxh | 6.3 | Maven | org.eclipse.jetty:jetty-http | 9.4.40.v20210413 | 12.0.12 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-wjpw-4j6x-6rwh | 3.7 | Maven | org.eclipse.jetty:jetty-http | 9.4.40.v20210413 | 12.0.31 | testdata/artifact/javareach_test.jar | -+-------------------------------------+------+-----------+---------------------------------------------+------------------+---------------+--------------------------------------+ -| Uncalled vulnerabilities | | | | | | | -+-------------------------------------+------+-----------+---------------------------------------------+------------------+---------------+--------------------------------------+ -| https://osv.dev/GHSA-c28r-hw5m-5gv3 | 7.9 | Maven | com.amazonaws:aws-java-sdk-s3 | 1.11.327 | 1.12.261 | testdata/artifact/javareach_test.jar | -| https://osv.dev/GHSA-7r82-7xv7-xcpj | 5.3 | Maven | org.apache.httpcomponents:httpclient | 4.5.5 | 4.5.13 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-3gh6-v5v9-6v9j | 3.5 | Maven | org.eclipse.jetty:jetty-servlets | 9.4.40.v20210413 | 9.4.52 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-gwcr-j4wh-j3cq | 5.3 | Maven | org.eclipse.jetty:jetty-servlets | 9.4.40.v20210413 | 9.4.41 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-j26w-f9rq-mr2q | 5.3 | Maven | org.eclipse.jetty:jetty-servlets | 9.4.40.v20210413 | 9.4.54 | testdata/artifact/javareach_test.jar | @@ -4038,8 +4041,8 @@ Total 4 packages affected by 57 known vulnerabilities (18 Critical, 30 High, 7 M Scanning dir ./testdata/artifact/javareach_test.jar Scanned /testdata/artifact/javareach_test.jar file and found 21 packages -Total 8 packages affected by 63 known vulnerabilities (18 Critical, 32 High, 10 Medium, 3 Low, 0 Unknown) from 1 ecosystem. -62 vulnerabilities can be fixed. +Total 8 packages affected by 64 known vulnerabilities (18 Critical, 33 High, 10 Medium, 3 Low, 0 Unknown) from 1 ecosystem. +63 vulnerabilities can be fixed. +-------------------------------------+------+-----------+---------------------------------------------+------------------+---------------+--------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | @@ -4047,6 +4050,7 @@ Total 8 packages affected by 63 known vulnerabilities (18 Critical, 32 High, 10 | https://osv.dev/GHSA-c28r-hw5m-5gv3 | 7.9 | Maven | com.amazonaws:aws-java-sdk-s3 | 1.11.327 | 1.12.261 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-72hv-8253-57qq | 6.9 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.18.6 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-h46c-h94j-95f3 | 8.7 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.15.0 | testdata/artifact/javareach_test.jar | +| https://osv.dev/GHSA-r7wm-3cxj-wff9 | 8.7 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.18.8 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-288c-cq4h-88gq | 7.5 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.6.7.4 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-4gq5-ch57-c2mg | 9.8 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.7.9.5 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-4w82-r329-3q67 | 9.8 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.6.7.4 | testdata/artifact/javareach_test.jar | @@ -4119,8 +4123,8 @@ Total 8 packages affected by 63 known vulnerabilities (18 Critical, 32 High, 10 Scanning dir ./testdata/artifact/javareach_test.jar Scanned /testdata/artifact/javareach_test.jar file and found 21 packages -Total 8 packages affected by 63 known vulnerabilities (18 Critical, 32 High, 10 Medium, 3 Low, 0 Unknown) from 1 ecosystem. -62 vulnerabilities can be fixed. +Total 8 packages affected by 64 known vulnerabilities (18 Critical, 33 High, 10 Medium, 3 Low, 0 Unknown) from 1 ecosystem. +63 vulnerabilities can be fixed. +-------------------------------------+------+-----------+---------------------------------------------+------------------+---------------+--------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | @@ -4128,6 +4132,7 @@ Total 8 packages affected by 63 known vulnerabilities (18 Critical, 32 High, 10 | https://osv.dev/GHSA-c28r-hw5m-5gv3 | 7.9 | Maven | com.amazonaws:aws-java-sdk-s3 | 1.11.327 | 1.12.261 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-72hv-8253-57qq | 6.9 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.18.6 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-h46c-h94j-95f3 | 8.7 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.15.0 | testdata/artifact/javareach_test.jar | +| https://osv.dev/GHSA-r7wm-3cxj-wff9 | 8.7 | Maven | com.fasterxml.jackson.core:jackson-core | 2.14.0 | 2.18.8 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-288c-cq4h-88gq | 7.5 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.6.7.4 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-4gq5-ch57-c2mg | 9.8 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.7.9.5 | testdata/artifact/javareach_test.jar | | https://osv.dev/GHSA-4w82-r329-3q67 | 9.8 | Maven | com.fasterxml.jackson.core:jackson-databind | 2.6.7.1 | 2.6.7.4 | testdata/artifact/javareach_test.jar | @@ -5133,7 +5138,7 @@ Filtered 1 local/unscannable package/s from the scan. Loaded Debian local db from /osv-scanner/Debian/all.zip Loaded Go local db from /osv-scanner/Go/all.zip -Total 22 packages affected by 224 known vulnerabilities (26 Critical, 94 High, 70 Medium, 6 Low, 28 Unknown) from 2 ecosystems. +Total 23 packages affected by 225 known vulnerabilities (26 Critical, 94 High, 70 Medium, 7 Low, 28 Unknown) from 2 ecosystems. 13 vulnerabilities can be fixed. +---------------------------------------+------+-----------+--------------------------------+------------------------------------+-----------------------------------+-------------------------------------------------+ @@ -5172,6 +5177,7 @@ Total 22 packages affected by 224 known vulnerabilities (26 Critical, 94 High, 7 | https://osv.dev/DEBIAN-CVE-2016-2781 | 6.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2024-0684 | 5.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3482-1 | | Debian | debian-archive-keyring | 2017.5+deb9u2 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-53910 | 2.1 | Debian | diffutils | 1:3.5-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5147-1 | 9.8 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-6297 | 8.2 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2026-2219 | 7.5 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -5408,7 +5414,7 @@ Filtered 1 local/unscannable package/s from the scan. Loaded Debian local db from /osv-scanner/Debian/all.zip Loaded Go local db from /osv-scanner/Go/all.zip -Total 22 packages affected by 224 known vulnerabilities (26 Critical, 94 High, 70 Medium, 6 Low, 28 Unknown) from 2 ecosystems. +Total 23 packages affected by 225 known vulnerabilities (26 Critical, 94 High, 70 Medium, 7 Low, 28 Unknown) from 2 ecosystems. 13 vulnerabilities can be fixed. +---------------------------------------+------+-----------+--------------------------------+------------------------------------+-----------------------------------+-------------------------------------------------+ @@ -5447,6 +5453,7 @@ Total 22 packages affected by 224 known vulnerabilities (26 Critical, 94 High, 7 | https://osv.dev/DEBIAN-CVE-2016-2781 | 6.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2024-0684 | 5.5 | Debian | coreutils | 8.26-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DLA-3482-1 | | Debian | debian-archive-keyring | 2017.5+deb9u2 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | +| https://osv.dev/DEBIAN-CVE-2026-53910 | 2.1 | Debian | diffutils | 1:3.5-3 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DSA-5147-1 | 9.8 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2025-6297 | 8.2 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | | https://osv.dev/DEBIAN-CVE-2026-2219 | 7.5 | Debian | dpkg | 1.18.25 | -- | testdata/sbom-insecure/postgres-stretch.cdx.xml | @@ -6137,13 +6144,14 @@ Total 1 package affected by 1 known vulnerability (0 Critical, 0 High, 0 Medium, [TestCommand_MoreLockfiles/gems.locked - 1] Scanned /testdata/locks-scalibr/gems.locked file and found 26 packages -Total 2 packages affected by 16 known vulnerabilities (0 Critical, 3 High, 3 Medium, 6 Low, 4 Unknown) from 1 ecosystem. -16 vulnerabilities can be fixed. +Total 2 packages affected by 17 known vulnerabilities (0 Critical, 3 High, 3 Medium, 7 Low, 4 Unknown) from 1 ecosystem. +17 vulnerabilities can be fixed. +-------------------------------------+------+-----------+----------+---------+---------------+------------------------------------+ | OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE | +-------------------------------------+------+-----------+----------+---------+---------------+------------------------------------+ | https://osv.dev/GHSA-9m3q-rhmv-5q44 | 7.5 | RubyGems | json | 2.10.1 | 2.10.2 | testdata/locks-scalibr/gems.locked | +| https://osv.dev/GHSA-x2f5-4prf-w687 | 3.7 | RubyGems | json | 2.10.1 | 2.19.9 | testdata/locks-scalibr/gems.locked | | https://osv.dev/GHSA-353f-x4gh-cqq8 | | RubyGems | nokogiri | 1.18.2 | 1.18.9 | testdata/locks-scalibr/gems.locked | | https://osv.dev/GHSA-5prr-v3j2-97mh | 6.3 | RubyGems | nokogiri | 1.18.2 | 1.19.4 | testdata/locks-scalibr/gems.locked | | https://osv.dev/GHSA-5v8h-3h3q-446p | 1.7 | RubyGems | nokogiri | 1.18.2 | 1.19.4 | testdata/locks-scalibr/gems.locked | diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml index 73dfa9bba8b..5693f347283 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml @@ -1938,7 +1938,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] } @@ -1989,7 +1989,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] } @@ -3082,7 +3082,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 25862 + content_length: 25943 body: | { "results": [ @@ -3138,7 +3138,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -3221,7 +3221,14 @@ interactions: ] }, {}, - {}, + { + "vulns": [ + { + "id": "DEBIAN-CVE-2026-53910", + "modified": "2026-07-23T10:00:15.236919Z" + } + ] + }, {}, { "vulns": [ @@ -3318,7 +3325,7 @@ interactions: }, { "id": "GHSA-xr7r-f8xq-vfvv", - "modified": "2026-02-04T03:18:48.377509Z" + "modified": "2026-07-21T15:00:40.929093Z" }, { "id": "GO-2022-0274", @@ -4230,7 +4237,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-42770", - "modified": "2026-06-16T05:00:12.124374Z" + "modified": "2026-07-21T05:00:16.807014Z" }, { "id": "DEBIAN-CVE-2026-45445", @@ -4761,7 +4768,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-34743", - "modified": "2026-07-13T12:00:11.362674Z" + "modified": "2026-07-21T23:00:14.683048Z" }, { "id": "DSA-5123-1", @@ -4779,7 +4786,7 @@ interactions: } headers: Content-Length: - - "25862" + - "25943" Content-Type: - application/json status: 200 OK @@ -4884,7 +4891,7 @@ interactions: }, { "id": "GO-2025-3956", - "modified": "2026-02-04T04:33:27.340869Z" + "modified": "2026-07-23T14:14:36.609580Z" }, { "id": "GO-2025-4006", @@ -4920,7 +4927,7 @@ interactions: }, { "id": "GO-2025-4014", - "modified": "2026-06-26T12:29:46.364453Z" + "modified": "2026-07-23T14:14:36.403566Z" }, { "id": "GO-2025-4015", @@ -4928,7 +4935,7 @@ interactions: }, { "id": "GO-2025-4155", - "modified": "2026-07-17T10:29:28.826194Z" + "modified": "2026-07-23T14:14:36.334594Z" }, { "id": "GO-2025-4175", @@ -4936,7 +4943,7 @@ interactions: }, { "id": "GO-2026-4337", - "modified": "2026-07-07T10:29:23.547454Z" + "modified": "2026-07-23T14:14:36.084142Z" }, { "id": "GO-2026-4340", @@ -4944,15 +4951,15 @@ interactions: }, { "id": "GO-2026-4341", - "modified": "2026-07-16T10:29:36.442242Z" + "modified": "2026-07-23T14:14:36.006729Z" }, { "id": "GO-2026-4342", - "modified": "2026-07-02T10:44:29.686144Z" + "modified": "2026-07-23T14:14:36.153870Z" }, { "id": "GO-2026-4601", - "modified": "2026-07-17T10:29:28.643038Z" + "modified": "2026-07-23T14:14:36.223456Z" }, { "id": "GO-2026-4602", @@ -4984,7 +4991,7 @@ interactions: }, { "id": "GO-2026-4946", - "modified": "2026-07-17T10:29:27.777936Z" + "modified": "2026-07-23T10:44:38.430505Z" }, { "id": "GO-2026-4947", @@ -5012,7 +5019,7 @@ interactions: }, { "id": "GO-2026-4981", - "modified": "2026-07-17T10:29:28.049309Z" + "modified": "2026-07-23T10:44:38.713700Z" }, { "id": "GO-2026-4982", @@ -5024,7 +5031,7 @@ interactions: }, { "id": "GO-2026-5037", - "modified": "2026-07-16T10:29:37.326923Z" + "modified": "2026-07-23T10:44:38.638231Z" }, { "id": "GO-2026-5038", diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml index b1ebac70c22..869c85aa07b 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml @@ -177,7 +177,7 @@ interactions: }, { "id": "CVE-2024-9143", - "modified": "2026-07-15T01:49:08.851917Z" + "modified": "2026-07-21T23:22:22.505096Z" }, { "id": "CVE-2025-9230", @@ -185,7 +185,7 @@ interactions: }, { "id": "CVE-2025-9231", - "modified": "2026-07-16T03:31:15.505625Z" + "modified": "2026-07-22T03:29:49.554500Z" } ] }, @@ -193,19 +193,19 @@ interactions: "vulns": [ { "id": "CVE-2025-11187", - "modified": "2026-07-15T02:13:38.516986Z" + "modified": "2026-07-22T03:36:06.401583Z" }, { "id": "CVE-2025-15467", - "modified": "2026-07-16T03:31:02.558731Z" + "modified": "2026-07-22T08:28:14.933667Z" }, { "id": "CVE-2025-15468", - "modified": "2026-07-15T02:13:49.606151Z" + "modified": "2026-07-22T03:36:12.269097Z" }, { "id": "CVE-2025-15469", - "modified": "2026-07-15T02:13:49.886884Z" + "modified": "2026-07-22T03:36:12.957175Z" }, { "id": "CVE-2025-4575", @@ -213,7 +213,7 @@ interactions: }, { "id": "CVE-2025-66199", - "modified": "2026-07-15T02:16:24.668466Z" + "modified": "2026-07-22T04:02:45.494277Z" }, { "id": "CVE-2025-68160", @@ -221,19 +221,19 @@ interactions: }, { "id": "CVE-2025-69418", - "modified": "2026-07-15T02:16:51.228766Z" + "modified": "2026-07-22T04:02:56.277882Z" }, { "id": "CVE-2025-69419", - "modified": "2026-07-15T02:16:51.350671Z" + "modified": "2026-07-22T03:08:25.611931Z" }, { "id": "CVE-2025-69420", - "modified": "2026-07-15T01:49:10.039695Z" + "modified": "2026-07-21T23:35:50.345574Z" }, { "id": "CVE-2025-69421", - "modified": "2026-07-15T02:16:51.491435Z" + "modified": "2026-07-22T03:08:25.889815Z" }, { "id": "CVE-2025-9230", @@ -241,15 +241,15 @@ interactions: }, { "id": "CVE-2025-9231", - "modified": "2026-07-16T03:31:15.505625Z" + "modified": "2026-07-22T03:29:49.554500Z" }, { "id": "CVE-2025-9232", - "modified": "2026-07-16T03:31:13.233310Z" + "modified": "2026-07-22T03:29:47.588675Z" }, { "id": "CVE-2026-22795", - "modified": "2026-07-15T02:17:35.174838Z" + "modified": "2026-07-22T03:08:41.700914Z" }, { "id": "CVE-2026-22796", @@ -261,7 +261,7 @@ interactions: }, { "id": "CVE-2026-28387", - "modified": "2026-07-15T01:49:10.342580Z" + "modified": "2026-07-21T23:33:38.117435Z" }, { "id": "CVE-2026-28388", @@ -273,11 +273,11 @@ interactions: }, { "id": "CVE-2026-28390", - "modified": "2026-07-15T02:18:28.219392Z" + "modified": "2026-07-22T03:08:49.755551Z" }, { "id": "CVE-2026-31789", - "modified": "2026-07-15T01:49:17.810727Z" + "modified": "2026-07-22T00:15:45.638429Z" }, { "id": "CVE-2026-31790", @@ -289,11 +289,11 @@ interactions: }, { "id": "CVE-2026-34181", - "modified": "2026-07-15T01:49:22.285695Z" + "modified": "2026-07-22T01:09:32.916854Z" }, { "id": "CVE-2026-34182", - "modified": "2026-07-18T08:59:26.165424Z" + "modified": "2026-07-22T03:57:37.436748Z" }, { "id": "CVE-2026-34183", @@ -321,7 +321,7 @@ interactions: }, { "id": "CVE-2026-42770", - "modified": "2026-07-15T18:01:31.880625Z" + "modified": "2026-07-22T08:28:19.756087Z" }, { "id": "CVE-2026-45445", @@ -329,15 +329,15 @@ interactions: }, { "id": "CVE-2026-45446", - "modified": "2026-07-15T01:49:18.782114Z" + "modified": "2026-07-22T00:25:03.723225Z" }, { "id": "CVE-2026-45447", - "modified": "2026-07-17T03:41:57.843057Z" + "modified": "2026-07-22T08:28:16.981141Z" }, { "id": "CVE-2026-7383", - "modified": "2026-07-15T01:49:22.207170Z" + "modified": "2026-07-22T00:45:50.255524Z" }, { "id": "CVE-2026-9076", diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml index 65e665f6700..67b4ac5a3aa 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Config_UnusedIgnores.yaml @@ -1246,7 +1246,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 25862 + content_length: 25943 body: | { "results": [ @@ -1302,7 +1302,7 @@ interactions: "vulns": [ { "id": "UBUNTU-CVE-2017-11164", - "modified": "2026-04-22T11:10:44.262299Z" + "modified": "2026-07-21T18:18:16.477212Z" } ] }, @@ -1385,7 +1385,14 @@ interactions: ] }, {}, - {}, + { + "vulns": [ + { + "id": "DEBIAN-CVE-2026-53910", + "modified": "2026-07-23T10:00:15.236919Z" + } + ] + }, {}, { "vulns": [ @@ -1482,7 +1489,7 @@ interactions: }, { "id": "GHSA-xr7r-f8xq-vfvv", - "modified": "2026-02-04T03:18:48.377509Z" + "modified": "2026-07-21T15:00:40.929093Z" }, { "id": "GO-2022-0274", @@ -2394,7 +2401,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-42770", - "modified": "2026-06-16T05:00:12.124374Z" + "modified": "2026-07-21T05:00:16.807014Z" }, { "id": "DEBIAN-CVE-2026-45445", @@ -2925,7 +2932,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-34743", - "modified": "2026-07-13T12:00:11.362674Z" + "modified": "2026-07-21T23:00:14.683048Z" }, { "id": "DSA-5123-1", @@ -2943,7 +2950,7 @@ interactions: } headers: Content-Length: - - "25862" + - "25943" Content-Type: - application/json status: 200 OK @@ -4014,7 +4021,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 25550 + content_length: 25631 body: | { "results": [ @@ -4129,7 +4136,14 @@ interactions: ] }, {}, - {}, + { + "vulns": [ + { + "id": "DEBIAN-CVE-2026-53910", + "modified": "2026-07-23T10:00:15.236919Z" + } + ] + }, {}, { "vulns": [ @@ -4226,7 +4240,7 @@ interactions: }, { "id": "GHSA-xr7r-f8xq-vfvv", - "modified": "2026-02-04T03:18:48.377509Z" + "modified": "2026-07-21T15:00:40.929093Z" }, { "id": "GO-2022-0274", @@ -5138,7 +5152,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-42770", - "modified": "2026-06-16T05:00:12.124374Z" + "modified": "2026-07-21T05:00:16.807014Z" }, { "id": "DEBIAN-CVE-2026-45445", @@ -5669,7 +5683,7 @@ interactions: }, { "id": "DEBIAN-CVE-2026-34743", - "modified": "2026-07-13T12:00:11.362674Z" + "modified": "2026-07-21T23:00:14.683048Z" }, { "id": "DSA-5123-1", @@ -5687,7 +5701,7 @@ interactions: } headers: Content-Length: - - "25550" + - "25631" Content-Type: - application/json status: 200 OK diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml index 67fbb43f2f3..7aa2e08d3ca 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml @@ -156,7 +156,7 @@ interactions: "vulns": [ { "id": "CVE-2022-2097", - "modified": "2026-07-15T02:03:28.831960Z" + "modified": "2026-07-22T02:23:27.551497Z" }, { "id": "CVE-2022-2274", @@ -176,7 +176,7 @@ interactions: }, { "id": "CVE-2022-3996", - "modified": "2026-07-15T02:06:16.986014Z" + "modified": "2026-07-22T02:08:07.451696Z" }, { "id": "CVE-2022-4203", @@ -184,15 +184,15 @@ interactions: }, { "id": "CVE-2022-4304", - "modified": "2026-07-15T02:06:38.672833Z" + "modified": "2026-07-22T02:08:34.951419Z" }, { "id": "CVE-2022-4450", - "modified": "2026-07-15T02:06:46.162417Z" + "modified": "2026-07-22T02:08:38.010563Z" }, { "id": "CVE-2023-0215", - "modified": "2026-07-15T02:05:20.506324Z" + "modified": "2026-07-22T02:24:48.755561Z" }, { "id": "CVE-2023-0216", @@ -204,7 +204,7 @@ interactions: }, { "id": "CVE-2023-0286", - "modified": "2026-07-15T02:07:47.026595Z" + "modified": "2026-07-22T02:08:57.551712Z" }, { "id": "CVE-2023-0401", @@ -212,15 +212,15 @@ interactions: }, { "id": "CVE-2023-0464", - "modified": "2026-07-15T02:07:48.595560Z" + "modified": "2026-07-22T02:08:59.652411Z" }, { "id": "CVE-2023-0465", - "modified": "2026-07-15T02:07:48.709174Z" + "modified": "2026-07-22T02:09:00.551625Z" }, { "id": "CVE-2023-0466", - "modified": "2026-07-15T02:07:49.160258Z" + "modified": "2026-07-22T02:09:01.434137Z" }, { "id": "CVE-2023-1255", @@ -228,7 +228,7 @@ interactions: }, { "id": "CVE-2023-2650", - "modified": "2026-07-15T02:08:12.779938Z" + "modified": "2026-07-22T02:24:50.124367Z" }, { "id": "CVE-2023-2975", @@ -240,7 +240,7 @@ interactions: }, { "id": "CVE-2023-4807", - "modified": "2026-07-15T02:09:41.221561Z" + "modified": "2026-07-22T02:50:16.435910Z" }, { "id": "CVE-2023-5363", @@ -248,7 +248,7 @@ interactions: }, { "id": "CVE-2023-5678", - "modified": "2026-07-15T02:10:32.235078Z" + "modified": "2026-07-22T02:50:40.334431Z" }, { "id": "CVE-2023-6129", @@ -268,7 +268,7 @@ interactions: }, { "id": "CVE-2024-2511", - "modified": "2026-07-15T01:49:14.116069Z" + "modified": "2026-07-21T23:56:44.789739Z" }, { "id": "CVE-2024-4603", @@ -276,23 +276,23 @@ interactions: }, { "id": "CVE-2024-4741", - "modified": "2026-07-15T01:49:10.761803Z" + "modified": "2026-07-21T23:45:08.942243Z" }, { "id": "CVE-2024-5535", - "modified": "2026-07-15T01:49:16.457767Z" + "modified": "2026-07-22T00:10:43.554969Z" }, { "id": "CVE-2024-6119", - "modified": "2026-07-15T01:49:16.704212Z" + "modified": "2026-07-22T00:13:05.803693Z" }, { "id": "CVE-2024-9143", - "modified": "2026-07-15T01:49:08.851917Z" + "modified": "2026-07-21T23:22:22.505096Z" }, { "id": "CVE-2025-15467", - "modified": "2026-07-16T03:31:02.558731Z" + "modified": "2026-07-22T08:28:14.933667Z" }, { "id": "CVE-2025-68160", @@ -300,19 +300,19 @@ interactions: }, { "id": "CVE-2025-69418", - "modified": "2026-07-15T02:16:51.228766Z" + "modified": "2026-07-22T04:02:56.277882Z" }, { "id": "CVE-2025-69419", - "modified": "2026-07-15T02:16:51.350671Z" + "modified": "2026-07-22T03:08:25.611931Z" }, { "id": "CVE-2025-69420", - "modified": "2026-07-15T01:49:10.039695Z" + "modified": "2026-07-21T23:35:50.345574Z" }, { "id": "CVE-2025-69421", - "modified": "2026-07-15T02:16:51.491435Z" + "modified": "2026-07-22T03:08:25.889815Z" }, { "id": "CVE-2025-9230", @@ -320,7 +320,7 @@ interactions: }, { "id": "CVE-2026-22795", - "modified": "2026-07-15T02:17:35.174838Z" + "modified": "2026-07-22T03:08:41.700914Z" }, { "id": "CVE-2026-22796", @@ -328,7 +328,7 @@ interactions: }, { "id": "CVE-2026-28387", - "modified": "2026-07-15T01:49:10.342580Z" + "modified": "2026-07-21T23:33:38.117435Z" }, { "id": "CVE-2026-28388", @@ -340,11 +340,11 @@ interactions: }, { "id": "CVE-2026-28390", - "modified": "2026-07-15T02:18:28.219392Z" + "modified": "2026-07-22T03:08:49.755551Z" }, { "id": "CVE-2026-31789", - "modified": "2026-07-15T01:49:17.810727Z" + "modified": "2026-07-22T00:15:45.638429Z" }, { "id": "CVE-2026-31790", @@ -356,7 +356,7 @@ interactions: }, { "id": "CVE-2026-34182", - "modified": "2026-07-18T08:59:26.165424Z" + "modified": "2026-07-22T03:57:37.436748Z" }, { "id": "CVE-2026-42766", @@ -368,7 +368,7 @@ interactions: }, { "id": "CVE-2026-42770", - "modified": "2026-07-15T18:01:31.880625Z" + "modified": "2026-07-22T08:28:19.756087Z" }, { "id": "CVE-2026-45445", @@ -376,15 +376,15 @@ interactions: }, { "id": "CVE-2026-45446", - "modified": "2026-07-15T01:49:18.782114Z" + "modified": "2026-07-22T00:25:03.723225Z" }, { "id": "CVE-2026-45447", - "modified": "2026-07-17T03:41:57.843057Z" + "modified": "2026-07-22T08:28:16.981141Z" }, { "id": "CVE-2026-7383", - "modified": "2026-07-15T01:49:22.207170Z" + "modified": "2026-07-22T00:45:50.255524Z" }, { "id": "CVE-2026-9076", diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_JavareachArchive.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_JavareachArchive.yaml index 5b7369ac21e..e52c6d9a60e 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_JavareachArchive.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_JavareachArchive.yaml @@ -170,7 +170,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 4558 + content_length: 4628 body: | { "results": [ @@ -196,6 +196,10 @@ interactions: { "id": "GHSA-h46c-h94j-95f3", "modified": "2026-02-04T03:44:39.385253Z" + }, + { + "id": "GHSA-r7wm-3cxj-wff9", + "modified": "2026-07-22T20:59:38.595267Z" } ] }, @@ -475,7 +479,7 @@ interactions: } headers: Content-Length: - - "4558" + - "4628" Content-Type: - application/json status: 200 OK @@ -650,7 +654,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 4558 + content_length: 4628 body: | { "results": [ @@ -676,6 +680,10 @@ interactions: { "id": "GHSA-h46c-h94j-95f3", "modified": "2026-02-04T03:44:39.385253Z" + }, + { + "id": "GHSA-r7wm-3cxj-wff9", + "modified": "2026-07-22T20:59:38.595267Z" } ] }, @@ -955,7 +963,7 @@ interactions: } headers: Content-Length: - - "4558" + - "4628" Content-Type: - application/json status: 200 OK @@ -1130,7 +1138,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 4558 + content_length: 4628 body: | { "results": [ @@ -1156,6 +1164,10 @@ interactions: { "id": "GHSA-h46c-h94j-95f3", "modified": "2026-02-04T03:44:39.385253Z" + }, + { + "id": "GHSA-r7wm-3cxj-wff9", + "modified": "2026-07-22T20:59:38.595267Z" } ] }, @@ -1435,7 +1447,7 @@ interactions: } headers: Content-Length: - - "4558" + - "4628" Content-Type: - application/json status: 200 OK diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_MoreLockfiles.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_MoreLockfiles.yaml index fff97993832..916dcfdc831 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_MoreLockfiles.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_MoreLockfiles.yaml @@ -474,7 +474,7 @@ interactions: proto: HTTP/2.0 proto_major: 2 proto_minor: 0 - content_length: 1226 + content_length: 1296 body: | { "results": [ @@ -495,6 +495,10 @@ interactions: { "id": "GHSA-9m3q-rhmv-5q44", "modified": "2026-02-04T03:22:18.343631Z" + }, + { + "id": "GHSA-x2f5-4prf-w687", + "modified": "2026-07-23T20:00:25.148390Z" } ] }, @@ -577,7 +581,7 @@ interactions: } headers: Content-Length: - - "1226" + - "1296" Content-Type: - application/json status: 200 OK diff --git a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml index 679a4d4886d..0b1a1ee88a2 100644 --- a/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml +++ b/cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_Transitive.yaml @@ -1136,7 +1136,7 @@ interactions: "ecosystem": "PyPI", "name": "certifi" }, - "version": "2026.6.17" + "version": "2026.7.22" }, { "package": { @@ -1463,7 +1463,7 @@ interactions: "ecosystem": "PyPI", "name": "certifi" }, - "version": "2026.6.17" + "version": "2026.7.22" }, { "package": {