vulnerabilities

package
v0.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 11, 2026 License: AGPL-3.0, AGPL-3.0-only Imports: 17 Imported by: 0

Documentation

Overview

Package vulnerabilities is the single lint module that reports known vulnerabilities affecting a project's dependencies. Per file it canonicalizes advisory observations from two sources — the OSV-API correlation attached to the file's dependencies, plus a per-file osv-scanner run — into one finding per advisory, so a CVE observed by both is reported exactly once with one verdict. It supersedes the freshness module's vulnerability findings and the standalone osv module, which produced the duplicate reports. The old "osv" module/config key still resolves here (see the lint engine's module aliases).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL