From df6750ebe4b4a03ab3d6186a0bf0a5695d0c585a Mon Sep 17 00:00:00 2001 From: prabhu Date: Wed, 31 Jan 2024 12:09:00 +0000 Subject: [PATCH] Prefer CVE alias over others (#87) Signed-off-by: Prabhu Subramanian --- pyproject.toml | 2 +- vdb/lib/osv.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index d6c5f7c..3141ad0 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "appthreat-vulnerability-db" -version = "5.6.0" +version = "5.6.1" description = "AppThreat's vulnerability database and package search library with a built-in file based storage. OSV, CVE, GitHub, npm are the primary sources of vulnerabilities." authors = [ {name = "Team AppThreat", email = "cloud@appthreat.com"}, diff --git a/vdb/lib/osv.py b/vdb/lib/osv.py index 9f1aec4..eef50d1 100644 --- a/vdb/lib/osv.py +++ b/vdb/lib/osv.py @@ -124,7 +124,7 @@ def to_vuln(self, cve_data): # Try to locate the CVE id from the aliases section if not cve_id.startswith("CVE") and not cve_id.startswith("RUSTSEC"): for i in aliases: - if not i.startswith("OSV"): + if i.startswith("CVE"): cve_id = i break assigner = "OSV"